Description
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
No analysis available yet.
Remediation
Vendor Workaround
The deploy directory can be restricted by making changes to runtime jetty configuration.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19934 | The deploy directory in PingFederate runtime nodes is reachable to unauthorized users. |
References
History
Mon, 19 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pingidentity
Pingidentity pingfederate |
|
| CPEs | cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:* cpe:2.3:a:pingidentity:pingfederate:12.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Pingidentity
Pingidentity pingfederate |
Status: PUBLISHED
Assigner: Ping Identity
Published:
Updated: 2024-08-01T22:43:34.512Z
Reserved: 2024-01-17T17:27:24.578Z
Link: CVE-2024-22377
Updated: 2024-08-01T22:43:34.512Z
Status : Modified
Published: 2024-07-09T23:15:10.620
Modified: 2024-11-21T08:56:09.157
Link: CVE-2024-22377
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD