CVE-2024-57971: Critical severity knowage server vulnerability
Published Feb 16, 2025
·Updated
DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.
Affected Software
1 affected component
Knowage Knowage Server<8.1.30
Event History
Feb 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What are the potential risks associated with CVE-2024-57971?
CVE-2024-57971 may allow an attacker to manipulate JNDI resources, leading to unauthorized database access or data leaks.
2
What is the severity of CVE-2024-57971?
CVE-2024-57971 is rated with a severity level that indicates a medium risk, primarily due to potential information exposure.
3
How do I fix CVE-2024-57971?
To fix CVE-2024-57971, upgrade your Knowage Server to version 8.1.30 or later to ensure proper validation of JNDI names.
4
Which versions of Knowage Server are affected by CVE-2024-57971?
CVE-2024-57971 affects all versions of Knowage Server prior to 8.1.30.
5
What component in Knowage is impacted by CVE-2024-57971?
CVE-2024-57971 specifically impacts the DataSourceResource.java file within the SpagoBI API support of Knowage Server.