CVE Vulnerabilities

CVE-2022-23721

Use of Multiple Resources with Duplicate Identifier

Published: Apr 25, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.

Weakness

The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required.

Affected Software

Name Vendor Start Version End Version
Pingid_integration_for_windows_login Pingidentity * 2.9 (excluding)

Potential Mitigations

References