Sensitive Information Disclosure in PingCentral by PingIdentity
CVE-2022-23726
What is CVE-2022-23726?
PingCentral prior to the specified versions is vulnerable to information disclosure, as it exposes Spring Boot actuator endpoints. These endpoints, when accessed without proper administrative authentication, can return a considerable amount of sensitive information regarding the application's environment and configuration. This vulnerability poses a significant risk as it can potentially allow attackers to gain insightful details about the system, leading to further exploitation. Organizations using PingCentral should ensure they are on the latest versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PingCentral java 1.10
PingCentral java 1.9 < 1.9.3
PingCentral java 1.8 < 1.8.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
