First published: Thu Jun 30 2022(Updated: )
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingid Integration For Windows Login | <2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23725 is a vulnerability in PingID Windows Login prior to version 2.8 that does not properly set permissions on the Windows Registry entries used to store sensitive API keys.
CVE-2022-23725 has a severity rating of high (5.5).
CVE-2022-23725 affects PingID Windows Login versions prior to 2.8 by not properly setting permissions on Windows Registry entries.
To fix CVE-2022-23725, update PingID Windows Login to version 2.8 or higher.
More information about CVE-2022-23725 can be found in the PingID documentation and downloads page.