CVE-2021-41770

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
07/10/2021
Last modified:
07/11/2023

Description

Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:* 10.3.1 (excluding)