CVE-2023-37283: Authentication Bypass via HTML Form & Identifier First Adapter
Published Oct 25, 2023
·Updated
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
Affected Software
4 affected components
pingidentity Pingfederate>=10.3.0<=10.3.12
pingidentity Pingfederate>=11.1.0<=11.1.7
pingidentity Pingfederate>=11.2.0<=11.2.6
pingidentity Pingfederate=11.3.0
Event History
Oct 25, 2023
CVE Published
via MITRE·01:24 AM
Data Sourced
via MITRE·01:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this authentication bypass vulnerability?
The vulnerability ID is CVE-2023-37283.
2
What is the severity of CVE-2023-37283?
The severity of CVE-2023-37283 is critical.
3
Which software is affected by CVE-2023-37283?
PingFederate versions 10.3.0 to 10.3.12, 11.1.0 to 11.1.7, and 11.2.0 to 11.2.6 are affected by CVE-2023-37283.
4
How does the authentication bypass work in CVE-2023-37283?
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter.
5
How can I fix CVE-2023-37283?
To fix CVE-2023-37283, it is recommended to update to a patched version of PingFederate.