Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-21409 Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 12 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Pingidentity
Pingidentity pingaccess
CPEs cpe:2.3:a:pingidentity:pingaccess:*:*:*:*:*:*:*:*
Vendors & Products Pingidentity
Pingidentity pingaccess
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 Nov 2024 23:00:00 +0000

Type Values Removed Values Added
Description Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
Title Access rules for PingAccess may be circumvented with URL-encoded characters
Weaknesses CWE-177
CWE-20
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/S:P/AU:Y/RE:M/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Ping Identity

Published:

Updated: 2024-11-12T18:51:50.901Z

Reserved: 2024-02-29T23:52:30.472Z

Link: CVE-2024-23983

cve-icon Vulnrichment

Updated: 2024-11-12T18:51:31.345Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-11T23:15:05.217

Modified: 2024-11-12T13:55:21.227

Link: CVE-2024-23983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.