CVE-2021-41770

Publication date

2021-10-07 06:24:36

Family

Ping Identity

State

PUBLISHED

Description

Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.