First published: Fri Jan 29 2021(Updated: )
The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section. Remediated in >= 8.3.0.9, >= 9.0.0.1, and >= 9.1.0.0 GA.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho | >=7.0.0<8.3.0.9 | |
Hitachi Vantara Pentaho | >=9.0.0<9.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Hitachi Vantara Pentaho vulnerability is CVE-2020-24669.
The severity of CVE-2020-24669 is medium, with a severity value of 5.4.
The affected software for CVE-2020-24669 is Hitachi Vantara Pentaho versions 7.x - 8.x and versions 9.0.0 - 9.0.0.1.
The CWE category for CVE-2020-24669 is CWE-79 (Cross-Site Scripting).
An attacker can exploit CVE-2020-24669 by injecting arbitrary JavaScript code through the 'Analysis Report Description' field in the 'About this Report' section of the New Analysis Report in Hitachi Vantara Pentaho.