CVE-2023-50165: SSRF
Published Jan 31, 2024
·Updated
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
Affected Software
1 affected component
Pega Platform>=8.2.1<=23.1.0
Event History
Jan 31, 2024
CVE Published
via MITRE·05:21 PM
Data Sourced
via MITRE·05:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-50165?
CVE-2023-50165 is considered a medium severity vulnerability due to its potential to expose sensitive file contents.
2
Which versions of Pega Platform are affected by CVE-2023-50165?
CVE-2023-50165 affects Pega Platform versions from 8.2.1 to 23.1.0.
3
How do I fix CVE-2023-50165?
To remediate CVE-2023-50165, upgrade your Pega Platform version to the latest stable release beyond 23.1.0.
4
What is the impact of CVE-2023-50165 on data security?
The impact of CVE-2023-50165 is the potential unauthorized access to sensitive information contained in generated PDF files.
5
Is there a workaround for CVE-2023-50165?
As of now, there are no official workarounds for CVE-2023-50165; the recommended action is to upgrade the software.