ZeroHour

CVE-2021-42000

CVSS 3.1
6.5 medium
EPSS
<1%p43
Published
()
Modified
Description

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.

Vendors
pingidentity
Products
pingfederate
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.