VulnerabilityModified
CVE-2021-42000
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.
MEDIUM 6.5EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.53% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- pingidentity/pingfederate
- Source
- responsible-disclosure@pingidentity.com
References
- https://docs.pingidentity.com/bundle/pingfederate-103/page/hhm1634833631515.htmlRelease Notes, Vendor Advisory
- https://www.pingidentity.com/en/resources/downloads/pingfederate.htmlVendor Advisory
- https://docs.pingidentity.com/bundle/pingfederate-103/page/hhm1634833631515.htmlRelease Notes, Vendor Advisory
- https://www.pingidentity.com/en/resources/downloads/pingfederate.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.