First published: Wed Oct 25 2023(Updated: )
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingfederate | >=10.3.0<=10.3.12 | |
Pingidentity Pingfederate | >=11.1.0<=11.1.7 | |
Pingidentity Pingfederate | >=11.2.0<=11.2.6 | |
Pingidentity Pingfederate | =11.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39219 is a vulnerability in PingFederate Administrative Console that allows the console to become unresponsive with crafted Java class loading enumeration requests.
The PingFederate software versions affected by CVE-2023-39219 are 10.3.0 to 10.3.12, 11.1.0 to 11.1.7, 11.2.0 to 11.2.6, and 11.3.
CVE-2023-39219 has a severity rating of high, with a CVSS score of 7.5.
To fix CVE-2023-39219, you should update your PingFederate software to a version that is not affected by the vulnerability.
You can find more information about CVE-2023-39219 in the PingFederate documentation and downloads page.