CVE-2022-23721: PingID integration for Windows login duplicate username collision.
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of PingID integration for Windows login?
The vulnerability ID is CVE-2022-23721.
What is the severity level of CVE-2022-23721?
The severity level of CVE-2022-23721 is low.
How does PingID integration for Windows login prior to 2.9 handle duplicate usernames?
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.
How can the vulnerability be fixed?
To fix CVE-2022-23721, it is recommended to update PingID integration for Windows login to version 2.9 or above.
Where can I find more information about CVE-2022-23721?
More information about CVE-2022-23721 can be found at the following link: [https://docs.pingidentity.com/r/en-us/pingid/davinci_pingid_windows_login_relnotes_2.9](https://docs.pingidentity.com/r/en-us/pingid/davinci_pingid_windows_login_relnotes_2.9)