CVE-2021-41770: XEE
Published Oct 7, 2021
·Updated
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
Affected Software
1 affected component
pingidentity Pingfederate<10.3.1
Event History
Oct 7, 2021
CVE Published
via MITRE·06:24 AM
Data Sourced
via MITRE·06:24 AM
Description
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-41770?
CVE-2021-41770 is a vulnerability in Ping Identity PingFederate before version 10.3.1 that mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
2
What is the severity of CVE-2021-41770?
CVE-2021-41770 has a severity value of 7.5, which is considered high.
3
How does CVE-2021-41770 affect PingFederate?
CVE-2021-41770 affects PingFederate versions before 10.3.1, where it can lead to an XXE attack and XML file disclosure.
4
How can I fix CVE-2021-41770?
To fix CVE-2021-41770, users are advised to update PingFederate to version 10.3.1 or above.
5
Where can I find more information about CVE-2021-41770?
You can find more information about CVE-2021-41770 in the PingIdentity documentation and download page.