CVE-2024-23983: Ping Identity Pingaccess
Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
Affected products
- Ping Identity Pingaccess: from 8.1.0, before 8.1.1 (fixed in 8.1.1); from 8.0.0, before 8.0.4 (fixed in 8.0.4); from 7.3.0, before 7.3.5 (fixed in 7.3.5); from 7.2.0, before 7.2.4 (fixed in 7.2.4); from 7.1.0, before 7.1.5 (fixed in 7.1.5); from 7.0.0, before 7.0.8 (fixed in 7.0.8); …
- Pingidentity Pingaccess: from 8.1.0, before 8.1.1 (fixed in 8.1.1); from 8.0.0, before 8.0.4 (fixed in 8.0.4); from 7.3.0, before 7.3.5 (fixed in 7.3.5); from 7.2.0, before 7.2.4 (fixed in 7.2.4); from 7.1.0, before 7.1.5 (fixed in 7.1.5); from 7.0.0, before 7.0.8 (fixed in 7.0.8); …
Published 2024-11-11. Last modified 2026-06-17.