First published: Wed May 04 2022(Updated: )
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingid Integration For Windows Login | <2.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23724 is a vulnerability that allows the forging of an authentication token to other users within a tenant organization by using static encryption key material.
CVE-2022-23724 has a severity rating of 8.1 (high).
The Pingidentity Pingid Integration For Windows Login software version up to 2.4.2 is affected by CVE-2022-23724.
To exploit CVE-2022-23724, an attacker must have compromised user credentials and can bypass MFA by redirecting an authentication flow to a target user.
Yes, you can refer to the documentation and downloads provided by PingIdentity for more information on CVE-2022-23724. Documentation: [link], Downloads: [link]