First published: Wed Sep 11 2024(Updated: )
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho | <10.1.0.0<9.3.0.8>=8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28981 is considered a high severity vulnerability due to its potential to expose sensitive database passwords.
To fix CVE-2024-28981, update your Hitachi Vantara Pentaho Data Integration & Analytics to version 10.1.0.0 or 9.3.0.8 and above.
CVE-2024-28981 affects Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.1.0.0, 9.3.0.8, and including 8.3.x.
CVE-2024-28981 discloses database passwords through metadata injectable fields during search operations.
There are no known workarounds for CVE-2024-28981; the only solution is to upgrade to a secure version.