9.8
CVSSv3

CVE-2023-40545

Published: 06/02/2024 Updated: 13/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

Vulnerable Product Search on Vulmon Subscribe to Product

pingidentity pingfederate 11.3.0