Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-27935

Опубликовано: 04 дек. 2025
Источник: nvd
EPSS Низкий

Описание

The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

EPSS

Процентиль: 29%
0.00106
Низкий

Дефекты

CWE-306

Связанные уязвимости

github
2 месяца назад

The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

EPSS

Процентиль: 29%
0.00106
Низкий

Дефекты

CWE-306