CVE-2023-40545
EUVD-2023-4511606.02.2024, 18:15
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pingidentity | pingfederate | 11.3.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| pingidentity | pingfederate | 11.3.0 ≤ 𝑥 ≤ 11.3.2 | ADP |
Common Weakness Enumeration