HTTP Request Smuggling Vulnerability in Ping Identity PingAccess
CVE-2021-31923
5.3MEDIUM
What is CVE-2021-31923?
Ping Identity PingAccess versions prior to 5.3.3 are susceptible to HTTP request smuggling attacks due to improper handling of request headers. Attackers can exploit this vulnerability by manipulating HTTP headers, potentially leading to unauthorized data access or service disruption. It is essential for organizations using these affected versions to apply security updates promptly to mitigate this risk.
Affected Version(s)
PingAccess 5.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ping Identity credits Portswigger Research for the discovery of this vulnerability.
Ping Identity credits MUFG Union Bank for their responsible disclosure.