Description
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
Published: 2024-11-11
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-21409 Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
History

Tue, 12 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Pingidentity
Pingidentity pingaccess
CPEs cpe:2.3:a:pingidentity:pingaccess:*:*:*:*:*:*:*:*
Vendors & Products Pingidentity
Pingidentity pingaccess
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 Nov 2024 23:00:00 +0000

Type Values Removed Values Added
Description Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
Title Access rules for PingAccess may be circumvented with URL-encoded characters
Weaknesses CWE-177
CWE-20
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/S:P/AU:Y/RE:M/U:Amber'}


Subscriptions

Pingidentity Pingaccess
cve-icon MITRE

Status: PUBLISHED

Assigner: Ping Identity

Published:

Updated: 2024-11-12T18:51:50.901Z

Reserved: 2024-02-29T23:52:30.472Z

Link: CVE-2024-23983

cve-icon Vulnrichment

Updated: 2024-11-12T18:51:31.345Z

cve-icon NVD

Status : Deferred

Published: 2024-11-11T23:15:05.217

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-23983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses