CVE-2020-24665: Medium severity hitachi vantara vulnerability
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition. Specifically, the vulnerability lies in the 'dashboardXml' parameter. Remediated in >= 7.1.0.25, >= 8.2.0.6, >= 8.3.0.0 GA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Hitachi Vantara Pentaho vulnerability?
The vulnerability ID for this Hitachi Vantara Pentaho vulnerability is CVE-2020-24665.
What is the severity of CVE-2020-24665?
The severity of CVE-2020-24665 is medium with a CVSS score of 6.5.
What is the affected software for CVE-2020-24665?
The affected software for CVE-2020-24665 is Hitachi Vantara Pentaho versions 7.x - 8.x.
What is the vulnerability description of CVE-2020-24665?
CVE-2020-24665 is an XML Entity Expansion injection vulnerability in the Dashboard Editor of Hitachi Vantara Pentaho, allowing authenticated remote users to trigger a denial of service (DoS) condition.
How can I mitigate the CVE-2020-24665 vulnerability?
To mitigate the CVE-2020-24665 vulnerability, update to a version of Hitachi Vantara Pentaho that is above 8.2.0.6 or 7.1.0.25 depending on your version.