First published: Mon Sep 27 2021(Updated: )
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingfederate | <10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-40329.
The title of this vulnerability is 'The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.'
The severity of CVE-2021-40329 is critical with a CVSS score of 9.8.
The software affected by CVE-2021-40329 is Ping Identity PingFederate before version 10.3.
To fix CVE-2021-40329, update Ping Identity PingFederate to version 10.3 or later.