CVE-2022-23726
30.09.2022, 15:15
PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.Enginsight
Vendor | Product | Version |
---|---|---|
pingidentity | pingcentral | 1.8 ≤ 𝑥 < 1.8.4 |
pingidentity | pingcentral | 1.9 ≤ 𝑥 < 1.9.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
References