The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section. Remediated in >= 8.3.0.9, >= 9.0.0.1, and >= 9.1.0.0 GA.
References
Link | Resource |
---|---|
http://www.hitachi.com/hirt/hitachi-sec/2020/601.html | Vendor Advisory |
https://www.accenture.com | Not Applicable |
http://www.hitachi.com/hirt/hitachi-sec/2020/601.html | Vendor Advisory |
https://www.accenture.com | Not Applicable |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.hitachi.com/hirt/hitachi-sec/2020/601.html - Vendor Advisory | |
References | () https://www.accenture.com - Not Applicable |
Information
Published : 2021-01-29 19:15
Updated : 2024-11-21 05:15
NVD link : CVE-2020-24669
Mitre link : CVE-2020-24669
CVE.ORG link : CVE-2020-24669
JSON object : View
Products Affected
hitachi
- vantara_pentaho
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')