ZeroHour

CVE-2022-23726

CVSS 3.1
4.9 medium
EPSS
<1%p48
Published
()
Modified
Description

PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.

Vendors
pingidentity
Products
pingcentral
Weakness
CWE-200, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.