CVE-2021-42000: Ping Identity PingFederate Password Reset and Password Change Mishandling with an authentication policy in parallel reset flows
Published Feb 10, 2022
·Updated
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.
Affected Software
7 affected components
pingidentity Pingfederate<=9.3.0
pingidentity Pingfederate>=10.0.0<=10.0.11
pingidentity Pingfederate>=10.1.0<=10.1.8
pingidentity Pingfederate>=10.2.0<=10.2.6
pingidentity Pingfederate>=10.3.0<=10.3.2
pingidentity Pingfederate=9.3.3
pingidentity Pingfederate=9.3.3-p15
Remediation
Information
PingFederate product patched versions 9.3.3-P16, 10.0.12, 10.1.9, 10.2.7, 10.3.3
Event History
Feb 10, 2022
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-42000?
CVE-2021-42000 is a vulnerability that allows an existing user to reset another existing user's password in Pingidentity Pingfederate versions up to 10.3.2.
2
How severe is CVE-2021-42000?
CVE-2021-42000 has a severity score of 6.5 out of 10.
3
Which software versions are affected by CVE-2021-42000?
CVE-2021-42000 affects Pingidentity Pingfederate versions up to 10.3.2.
4
How can I fix CVE-2021-42000?
To fix CVE-2021-42000, it is recommended to upgrade to the latest version of Pingidentity Pingfederate.
5
Where can I find more information about CVE-2021-42000?
You can find more information about CVE-2021-42000 in the Pingidentity Pingfederate documentation and downloads page.