CVE-2022-40724: Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint.
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40724?
CVE-2022-40724 is a vulnerability in PingFederate, specifically in the Local Identity Profiles '/pf/idprofile.ping' endpoint, that allows for Cross-Site Request Forgery (CSRF) through crafted GET requests.
How does CVE-2022-40724 affect PingFederate?
CVE-2022-40724 affects PingFederate versions 10.3.0 to 10.3.11, 11.0.0 to 11.0.6, 11.1.0 to 11.1.5, and 11.2.0 to 11.2.2.
What is the severity of CVE-2022-40724?
CVE-2022-40724 has a severity rating of 8.8 (high).
How can I fix CVE-2022-40724?
To fix CVE-2022-40724, you should update PingFederate to a version that is not affected by the vulnerability. Refer to the PingFederate documentation for guidance.
Where can I find more information about CVE-2022-40724?
More information about CVE-2022-40724 can be found in the PingFederate documentation at the provided reference link.