CVE-2022-23723
02.05.2022, 22:15
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.Enginsight
Vendor | Product | Version |
---|---|---|
pingidentity | pingone_mfa_integration_kit | 1.4 |
pingidentity | pingone_mfa_integration_kit | 1.4.1 |
pingidentity | pingone_mfa_integration_kit | 1.5 |
pingidentity | pingone_mfa_integration_kit | 1.5.1 |
pingidentity | pingone_mfa_integration_kit | 1.5.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-288 - Authentication Bypass Using an Alternate Path or ChannelA product requires authentication, but the product has an alternate path or channel that does not require authentication.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
References