CVE-2023-40148: PingFederate Server Side Request Forgery vulnerability
Published Apr 10, 2024
·Updated
Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.
Affected Software
1 affected component
PingFederate PingFederate
Event History
Apr 10, 2024
CVE Published
via MITRE·12:03 AM
Data Sourced
via MITRE·12:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-40148?
CVE-2023-40148 is classified as a high severity vulnerability due to its potential for server-side request forgery (SSRF) attacks.
2
How do I fix CVE-2023-40148?
To fix CVE-2023-40148, ensure you update to the latest version of PingFederate that addresses this vulnerability.
3
What type of vulnerability is CVE-2023-40148?
CVE-2023-40148 is a server-side request forgery (SSRF) vulnerability that allows unauthenticated HTTP requests.
4
Who is affected by CVE-2023-40148?
CVE-2023-40148 affects users of PingFederate across all versions prior to the patch.
5
What are the potential impacts of CVE-2023-40148?
The potential impacts of CVE-2023-40148 include unauthorized access to network resources and consumption of server-side resources.