CVE-2024-23316
May 31, 2024, 7:15 p.m.
Tags
Product(s) Impacted
Ping Identity PingAccess
- before 8.0.1
Description
HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests.
Weaknesses
Date
Published: May 31, 2024, 7:15 p.m.
Last Modified: May 31, 2024, 7:15 p.m.
Status : Received
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
responsible-disclosure@pingidentity.com
References
https://docs.pingidentity.com/
responsible-disclosure@pingidentity.com
https://support.pingidentity.com/
responsible-disclosure@pingidentity.com
https://www.pingidentity.com/
responsible-disclosure@pingidentity.com