Sensitive Information Disclosure in PingCentral by PingIdentity
CVE-2022-23726
5.4MEDIUM
What is CVE-2022-23726?
PingCentral prior to the specified versions is vulnerable to information disclosure, as it exposes Spring Boot actuator endpoints. These endpoints, when accessed without proper administrative authentication, can return a considerable amount of sensitive information regarding the application's environment and configuration. This vulnerability poses a significant risk as it can potentially allow attackers to gain insightful details about the system, leading to further exploitation. Organizations using PingCentral should ensure they are on the latest versions to mitigate this risk.
Affected Version(s)
PingCentral java 1.10
PingCentral java 1.9 < 1.9.3
PingCentral java 1.8 < 1.8.4