CVE-2023-40148
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
10/04/2024
Last modified:
15/04/2026
Description
Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.<br />
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://docs.pingidentity.com/r/en-us/pingfederate-120/tuj1708533127032
- https://www.pingidentity.com/en/resources/downloads/pingfederate/previous-releases.html
- https://docs.pingidentity.com/r/en-us/pingfederate-120/tuj1708533127032
- https://www.pingidentity.com/en/resources/downloads/pingfederate/previous-releases.html



