CVE-2020-24353: XSS
Published Nov 9, 2020
·Updated
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
Affected Software
1 affected component
Pega Pega Platform<8.4
Event History
Nov 9, 2020
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-24353.
2
What is the severity level of CVE-2020-24353?
CVE-2020-24353 has a severity level of medium.
3
How does CVE-2020-24353 occur?
CVE-2020-24353 occurs due to a XSS issue in Pega Platform before version 8.4.0, specifically through the stream rule parameters used in the request header.
4
What is the impact of CVE-2020-24353?
CVE-2020-24353 allows for cross-site scripting (XSS) attacks, which can lead to unauthorized access, information disclosure, and potential data manipulation on affected systems.
5
How can I fix CVE-2020-24353?
To mitigate the vulnerability, it is recommended to upgrade to Pega Platform version 8.4.0 or later, which addresses the XSS issue.