CVE-2024-22477: PingFederate OIDC Policy Management Editor Cross-Site Scripting
Published Jul 9, 2024
·Updated
A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.
Affected Software
6 affected components
pingidentity Pingfederate>=10.3.0<=10.3.13
pingidentity Pingfederate>=11.0.0<=11.0.9
pingidentity Pingfederate>=11.1.0<=11.1.9
pingidentity Pingfederate>=11.2.0<=11.2.8
pingidentity Pingfederate>=11.3.0<=11.3.4
pingidentity Pingfederate=12.0.0
Event History
Jul 9, 2024
CVE Published
via MITRE·11:01 PM
Data Sourced
via MITRE·11:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-22477?
CVE-2024-22477 is classified as a cross-site scripting vulnerability affecting the admin console.
2
How do I fix CVE-2024-22477?
To fix CVE-2024-22477, update PingFederate to a version beyond the affected ranges specified in the vulnerability report.
3
Who is affected by CVE-2024-22477?
Only administrators using the admin console OIDC Policy Management Editor are affected by CVE-2024-22477.
4
What versions of PingFederate are affected by CVE-2024-22477?
CVE-2024-22477 affects PingFederate versions from 10.3.0 to 10.3.13, 11.0.0 to 11.0.9, 11.1.0 to 11.1.9, 11.2.0 to 11.2.8, 11.3.0 to 11.3.4, and 12.0.0.
5
Can CVE-2024-22477 be exploited remotely?
CVE-2024-22477 cannot be exploited remotely as it is limited to authenticated admin console users.