First published: Tue Feb 06 2024(Updated: )
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
PingFederate | =11.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40545 is classified as a critical severity vulnerability due to its potential for authentication bypass.
To fix CVE-2023-40545, update PingFederate to a version that is not affected by this vulnerability.
CVE-2023-40545 affects PingFederate version 11.3.0.
CVE-2023-40545 is an authentication bypass vulnerability when using the client_secret_jwt authentication method.
Organizations using PingFederate version 11.3.0 with OAuth2 client_secret_jwt for authentication are at risk for CVE-2023-40545.