CVE-2024-28981: Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28981?
CVE-2024-28981 is considered a high severity vulnerability due to its potential to expose sensitive database passwords.
How do I fix CVE-2024-28981?
To fix CVE-2024-28981, update your Hitachi Vantara Pentaho Data Integration & Analytics to version 10.1.0.0 or 9.3.0.8 and above.
What products are affected by CVE-2024-28981?
CVE-2024-28981 affects Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.1.0.0, 9.3.0.8, and including 8.3.x.
What type of information is disclosed by CVE-2024-28981?
CVE-2024-28981 discloses database passwords through metadata injectable fields during search operations.
Is there a workaround for CVE-2024-28981?
There are no known workarounds for CVE-2024-28981; the only solution is to upgrade to a secure version.