CVE-2021-42000 MEDIUM

CVE-2021-42000: Ping Identity PingFederate Password Reset and Password Change Mishandling with an authentication policy in parallel reset flows

Vendor Ping Identity
Product PingFederate
Weakness CWE-285
Published February 10, 2022
Last update August 4, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.

Key dates

02Disclosure timeline

February 10, 2022 CVE published
August 4, 2024 Record updated