CVE-2024-22477

A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
1.8 LOW
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
Ping IdentityCNA
1.8 LOW
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
pingidentitypingfederate
10.3.0 ≤
𝑥
≤ 10.3.13
pingidentitypingfederate
11.0.0 ≤
𝑥
≤ 11.0.9
pingidentitypingfederate
11.1.0 ≤
𝑥
≤ 11.1.9
pingidentitypingfederate
11.2.0 ≤
𝑥
≤ 11.2.8
pingidentitypingfederate
11.3.0 ≤
𝑥
≤ 11.3.4
pingidentitypingfederate
12.0.0
𝑥
= Vulnerable software versions