CVE-2024-22377: PingFederate Runtime Node Path Traversal
Published Jul 9, 2024
·Updated
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
Affected Software
6 affected components
pingidentity Pingfederate>=10.3.0<=10.3.13
pingidentity Pingfederate>=11.0.0<=11.0.9
pingidentity Pingfederate>=11.1.0<=11.1.9
pingidentity Pingfederate>=11.2.0<=11.2.8
pingidentity Pingfederate>=11.3.0<=11.3.4
pingidentity Pingfederate=12.0.0
Event History
Jul 9, 2024
CVE Published
via MITRE·11:03 PM
Data Sourced
via MITRE·11:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-22377?
CVE-2024-22377 has a high severity rating due to unauthorized access to the deploy directory in PingFederate.
2
How do I fix CVE-2024-22377?
To remediate CVE-2024-22377, restrict access to the deploy directory to authorized users only.
3
Which versions of PingFederate are affected by CVE-2024-22377?
CVE-2024-22377 affects PingFederate versions from 10.3.0 to 10.3.13, 11.0.0 to 11.0.9, 11.1.0 to 11.1.9, 11.2.0 to 11.2.8, 11.3.0 to 11.3.4, and 12.0.0.
4
What is the impact of CVE-2024-22377?
The impact of CVE-2024-22377 is the potential exposure of sensitive configuration files to unauthorized users.
5
Is there a workaround for CVE-2024-22377?
A potential workaround for CVE-2024-22377 is to implement firewall rules to limit access to the PingFederate runtime nodes.