CVE-2022-23723: PingFederate PingOneMFA Integration Kit MFA Bypass
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23723?
CVE-2022-23723 is an MFA bypass vulnerability in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.
Which software is affected by CVE-2022-23723?
The PingFederate PingOne MFA Integration Kit versions 1.4, 1.4.1, 1.5, 1.5.1, and 1.5.2 are affected by CVE-2022-23723.
What is the severity of CVE-2022-23723?
CVE-2022-23723 has a severity rating of 7.7 (High).
How can I fix CVE-2022-23723?
To fix CVE-2022-23723, update to a patched version of the PingFederate PingOne MFA Integration Kit.
Where can I find more information about CVE-2022-23723?
You can find more information about CVE-2022-23723 in the official documentation: [link](https://docs.pingidentity.com/bundle/pingfederate-pingone-mfa-ik/page/wpt1599064234202.html) and [link](https://www.pingidentity.com/en/resources/downloads/pingfederate.html).