PingAccess Vulnerability: Request Smuggling Attack via Specially Crafted HTTP Headers
CVE-2024-23316

Currently unrated

Key Information:

Vendor
CVE Published:
31 May 2024

What is CVE-2024-23316?

HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests.

Affected Version(s)

PingAccess 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.