5.4
CVE-2022-23726
- EPSS 0.21%
- Veröffentlicht 30.09.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:49:11
- Quelle responsible-disclosure@pingide
- CVE-Watchlists
- Unerledigt
PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pingidentity ≫ Pingcentral Version >= 1.8 < 1.8.4
Pingidentity ≫ Pingcentral Version >= 1.9 < 1.9.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.436 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| responsible-disclosure@pingidentity.com | 5.4 | 1 | 4 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.