PingID Desktop prior to 1.7.3 has a misconfiguration in...
Critical severity
Unreviewed
Published
May 3, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Apr 30, 2022
Published to the GitHub Advisory Database
May 3, 2022
Last updated
Feb 1, 2023
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
References