First published: Thu Oct 07 2021(Updated: )
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
Credit: cve@mitre.org responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingfederate | <10.3.1 | |
<10.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41770 is a vulnerability in Ping Identity PingFederate before version 10.3.1 that mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
CVE-2021-41770 has a severity value of 7.5, which is considered high.
CVE-2021-41770 affects PingFederate versions before 10.3.1, where it can lead to an XXE attack and XML file disclosure.
To fix CVE-2021-41770, users are advised to update PingFederate to version 10.3.1 or above.
You can find more information about CVE-2021-41770 in the PingIdentity documentation and download page.