PT-2023-12732 · Ping Identity · Pingid Integration For Windows Login

Publicado

2023-04-25

·

Atualizado

2023-05-04

·

CVE-2022-23721

CVSS v3.1

3.8

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions PingID integration for Windows login versions prior to 2.9
Description The issue arises from the PingID integration for Windows login not handling duplicate usernames. This can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.
Recommendations For versions prior to 2.9, update to version 2.9 or later to resolve the issue. As a temporary workaround, consider implementing unique username provisioning to minimize the risk of username collisions. Restrict access to the Windows login integration to minimize the risk of exploitation until the issue is resolved.

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-23721

Produtos afetados

Pingid Integration For Windows Login