CVE-2022-23723

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
02/05/2022
Last modified:
03/09/2022

Description

An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.4:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.5:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.5.2:*:*:*:*:*:*:*