CVE-2022-23723
HIGHPingFederate PingOne MFA Integration Kit - MFA Bypass via Adapter HTML Templates
Title source: llmDescription
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.pingidentity.com/en/resources/downloads/pingfederate.html
Release Notes, Vendor Advisory x_refsource_misc
https://docs.pingidentity.com/bundle/pingfederate-pingone-mfa-ik/page/wpt1599064234202.html
Scores
CVSS v3
7.7
EPSS
0.0081
EPSS Percentile
51.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Details
CWE
CWE-287
CWE-288
Status
published
Products (5)
pingidentity/pingone_mfa_integration_kit
1.4
pingidentity/pingone_mfa_integration_kit
1.4.1
pingidentity/pingone_mfa_integration_kit
1.5
pingidentity/pingone_mfa_integration_kit
1.5.1
pingidentity/pingone_mfa_integration_kit
1.5.2
Published
May 02, 2022
Tracked Since
Feb 18, 2026