CVE Database
/

CVE-2024-23316

Back to search

CVE-2024-23316

Published: May 31, 2024

Modified: Aug 1, 2024

PUBLISHED

Description

HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests.

VendorProductVersions

Ping Identity

PingAccess

affected
0 - < 8.0.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now