First published: Tue Apr 25 2023(Updated: )
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingfederate | >=10.3.0<=10.3.11 | |
Pingidentity Pingfederate | >=11.0.0<=11.0.6 | |
Pingidentity Pingfederate | >=11.1.0<=11.1.5 | |
Pingidentity Pingfederate | >=11.2.0<=11.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40724 is a vulnerability in PingFederate, specifically in the Local Identity Profiles '/pf/idprofile.ping' endpoint, that allows for Cross-Site Request Forgery (CSRF) through crafted GET requests.
CVE-2022-40724 affects PingFederate versions 10.3.0 to 10.3.11, 11.0.0 to 11.0.6, 11.1.0 to 11.1.5, and 11.2.0 to 11.2.2.
CVE-2022-40724 has a severity rating of 8.8 (high).
To fix CVE-2022-40724, you should update PingFederate to a version that is not affected by the vulnerability. Refer to the PingFederate documentation for guidance.
More information about CVE-2022-40724 can be found in the PingFederate documentation at the provided reference link.