Description
HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-20834 | HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: Ping Identity
Published:
Updated: 2024-08-01T22:59:32.210Z
Reserved: 2024-01-17T17:27:24.608Z
Link: CVE-2024-23316
Updated: 2024-08-01T22:59:32.210Z
Status : Deferred
Published: 2024-05-31T19:15:08.723
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-23316
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD