Sensitive Information Disclosure in PingCentral by PingIdentity
CVE-2022-23726

5.4MEDIUM

Key Information:

Vendor
CVE Published:
30 September 2022

What is CVE-2022-23726?

PingCentral prior to the specified versions is vulnerable to information disclosure, as it exposes Spring Boot actuator endpoints. These endpoints, when accessed without proper administrative authentication, can return a considerable amount of sensitive information regarding the application's environment and configuration. This vulnerability poses a significant risk as it can potentially allow attackers to gain insightful details about the system, leading to further exploitation. Organizations using PingCentral should ensure they are on the latest versions to mitigate this risk.

Affected Version(s)

PingCentral java 1.10

PingCentral java 1.9 < 1.9.3

PingCentral java 1.8 < 1.8.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-23726 : Sensitive Information Disclosure in PingCentral by PingIdentity