Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
References
Link | Resource |
---|---|
https://collaborate.pega.com/discussion/pega-security-advisory-c21 | Vendor Advisory |
Configurations
Information
Published : 2022-01-28 12:15
Updated : 2022-02-03 09:04
NVD link : CVE-2021-27654
Mitre link : CVE-2021-27654
JSON object : View
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Products Affected
pega
- infinity