Описание
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
Ссылки
- Release Notes
- https://support.pingidentity.com/s/article/SECADV040-PingFederate-OAuth-Client-Authentication-BypassPermissions Required
- Release Notes
- Release Notes
- https://support.pingidentity.com/s/article/SECADV040-PingFederate-OAuth-Client-Authentication-BypassPermissions Required
- Release Notes
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:pingidentity:pingfederate:11.3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00066
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-306
CWE-306
Связанные уязвимости
CVSS3: 8.8
github
около 2 лет назад
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
EPSS
Процентиль: 21%
0.00066
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-306
CWE-306