Description
Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
11.3.0 (custom) before 11.3.14
12.0.0 (custom) before 12.0.10
12.1.0 (custom) before 12.1.9
12.2.0 (custom) before 12.2.6
12.3.0 (custom) before 12.3.3
References
support.pingidentity.com/...e-rendering-in-redirectless-mode
www.pingidentity.com/...esources/downloads/pingfederate.html