CVE-2022-23726
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD
Description
PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.
Affected (2)
Products: Pingidentity: Pingcentral
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.8 to 1.8.4 |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-732
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
References (4)
Source: responsible-disclosure@pingidentity.com
Release NotesVendor Advisory
Source: responsible-disclosure@pingidentity.com
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Timeline
No history available yet.