PingOne MFA Integration Kit contains a vulnerability...
High severity
Unreviewed
Published
Jul 9, 2024
to the GitHub Advisory Database
•
Updated Aug 8, 2024
Description
Published by the National Vulnerability Database
Jul 9, 2024
Published to the GitHub Advisory Database
Jul 9, 2024
Last updated
Aug 8, 2024
PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentication does not require the second factor authentication from the user's existing registered devices. A threat actor might be able to exploit this vulnerability to authenticate as a target user if they have existing knowledge of the target user’s first-factor credentials.
References