Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2023-40545
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.001
EPSS Ranking
20.9%
CVSS Severity
CVSS v3 Score
8.8
References
https://docs.pingidentity.com/r/en-us/pingfederate-113/hro1701116403236
https://support.pingidentity.com/s/article/SECADV040-PingFederate-OAuth-Client-Authentication-Bypass
https://www.pingidentity.com/en/resources/downloads/pingfederate/previous-releases.html
https://docs.pingidentity.com/r/en-us/pingfederate-113/hro1701116403236
https://support.pingidentity.com/s/article/SECADV040-PingFederate-OAuth-Client-Authentication-Bypass
https://www.pingidentity.com/en/resources/downloads/pingfederate/previous-releases.html
Products affected by CVE-2023-40545
Pingidentity
»
Pingfederate
»
Version:
11.3.0
cpe:2.3:a:pingidentity:pingfederate:11.3.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved