CVE-2022-23726

MEDIUM

PingCentral 1.8-1.8.3 - Authenticated Exposure of Sensitive Information via Spring Boot Actuator Endpoints

Title source: llm
STIX 2.1

Description

PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0056
EPSS Percentile 42.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-732
Status published
Products (1)
pingidentity/pingcentral 1.8 - 1.8.4
Published Sep 30, 2022
Tracked Since Feb 18, 2026