CVE-2024-23316

May 31, 2024, 7:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Ping Identity PingAccess

  • before 8.0.1

Source

responsible-disclosure@pingidentity.com

Tags

CVE-2024-23316 details

Published : May 31, 2024, 7:15 p.m.
Last Modified : May 31, 2024, 7:15 p.m.

Description

HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description

References

URL Source
https://docs.pingidentity.com/r/en-us/pingaccess-80/pa_801_rn responsible-disclosure@pingidentity.com
https://support.pingidentity.com/s/article/SECADV045-PA-HTTP-Smuggling responsible-disclosure@pingidentity.com
https://www.pingidentity.com/en/resources/downloads/pingaccess.html responsible-disclosure@pingidentity.com
This website uses the NVD API, but is not approved or certified by it.