Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PingID Integration for Windows Login MFA Bypass
Vulnerability Description
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
加密问题
Vulnerability Title
Ping Identity Windows PingId 信任管理问题漏洞
Vulnerability Description
Ping Identity Windows PingId是美国Ping Identity公司的一款可以为应用程序提供安全保障的软件。 PingId Integration for Windows Login 2.4.1 及之前版本存在信任管理问题漏洞,该漏洞源于使用静态加密密钥材料允许向租户组织内的其他用户伪造身份验证令牌。
CVSS Information
N/A
Vulnerability Type
N/A