Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
11.0.0 (custom)
affected
11.1.0 (custom)
affected
11.2.0 (custom)
affected
11.3.0 (custom)
affected
12.0.0 (custom)
affected
10.3.0 (custom)
affected
Description
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
11.0.0 (custom)
11.1.0 (custom)
11.2.0 (custom)
11.3.0 (custom)
12.0.0 (custom)
10.3.0 (custom)
References
docs.pingidentity.com/...s/pingfederate-120/lwu1707324350083
docs.pingidentity.com/...s/pingfederate-120/lwu1707324350083