Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
Configurations
No configuration.
History
12 Sep 2024, 12:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
12 Sep 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-12 00:15
Updated : 2024-09-12 12:35
NVD link : CVE-2024-28981
Mitre link : CVE-2024-28981
CVE.ORG link : CVE-2024-28981
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials