First published: Fri Sep 30 2022(Updated: )
PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingcentral | >=1.8<1.8.4 | |
Pingidentity Pingcentral | >=1.9<1.9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-23726.
The severity of CVE-2022-23726 is medium (4.9).
PingCentral versions prior to 1.8.4 and 1.9.3 are affected by CVE-2022-23726.
CVE-2022-23726 exposes Spring Boot actuator endpoints that, with administrative authentication, return large amounts of sensitive environmental and application information.
You can find more information about CVE-2022-23726 in the PingCentral documentation and PingCentral downloads page.