An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.
                
            References
                    | Link | Resource | 
|---|---|
| https://docs.pingidentity.com/bundle/pingfederate-pingone-mfa-ik/page/wpt1599064234202.html | Release Notes Vendor Advisory | 
| https://www.pingidentity.com/en/resources/downloads/pingfederate.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2022-05-02 15:15
Updated : 2022-09-02 20:55
NVD link : CVE-2022-23723
Mitre link : CVE-2022-23723
JSON object : View
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
Products Affected
                pingidentity
- pingone_mfa_integration_kit
 


