First published: Tue Jul 09 2024(Updated: )
A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
PingFederate | >=10.3.0<=10.3.13 | |
PingFederate | >=11.0.0<=11.0.9 | |
PingFederate | >=11.1.0<=11.1.9 | |
PingFederate | >=11.2.0<=11.2.8 | |
PingFederate | >=11.3.0<=11.3.4 | |
PingFederate | =12.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22477 is classified as a cross-site scripting vulnerability affecting the admin console.
To fix CVE-2024-22477, update PingFederate to a version beyond the affected ranges specified in the vulnerability report.
Only administrators using the admin console OIDC Policy Management Editor are affected by CVE-2024-22477.
CVE-2024-22477 affects PingFederate versions from 10.3.0 to 10.3.13, 11.0.0 to 11.0.9, 11.1.0 to 11.1.9, 11.2.0 to 11.2.8, 11.3.0 to 11.3.4, and 12.0.0.
CVE-2024-22477 cannot be exploited remotely as it is limited to authenticated admin console users.