Description
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28660 | Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials. |
References
History
Tue, 24 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | PingID Integration for Windows Login MFA Bypass | PingID Integration for Windows Login MFA Bypass |
Status: PUBLISHED
Assigner: Ping Identity
Published:
Updated: 2024-08-03T03:51:46.013Z
Reserved: 2022-01-19T00:00:00.000Z
Link: CVE-2022-23724
No data.
Status : Modified
Published: 2022-05-04T17:15:08.970
Modified: 2024-11-21T06:49:11.240
Link: CVE-2022-23724
No data.
OpenCVE Enrichment
No data.
EUVD