CVE-2021-42000

MEDIUM

PingFederate < 9.3.0 - Improper Authorization in Password Reset Flow

Title source: llm
STIX 2.1

Description

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.

References (2)

Core 2
Core References

Scores

CVSS v3 5.3
EPSS 0.0053
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-285
Status published
Products (2)
pingidentity/pingfederate 9.3.3 (2 CPE variants)
pingidentity/pingfederate < 9.3.0
Published Feb 10, 2022
Tracked Since Feb 18, 2026