Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
Configurations
No configuration.
History
No history.
Information
Published : 2024-09-12 00:15
Updated : 2024-09-12 12:35
NVD link : CVE-2024-28981
Mitre link : CVE-2024-28981
CVE.ORG link : CVE-2024-28981
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials