CVE-2021-27653: Medium severity PEGA Infinity vulnerability
Published Apr 1, 2021
·Updated
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
Affected Software
1 affected component
PEGA Infinity>=7.4.0<8.5.3
Event History
Apr 1, 2021
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-27653.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.'
3
What is the severity of CVE-2021-27653?
The severity of CVE-2021-27653 is medium with a severity value of 4.9.
4
What software versions are affected by CVE-2021-27653?
The Pega platform versions 7.4.0 - 8.5.x are affected by CVE-2021-27653.
5
How can the misconfiguration be fixed?
To fix the misconfiguration, update Pega platform to version 8.5.3 or apply the necessary patches.