CVE-2024-37362

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)   Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.   Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.
Configurations

No configuration.

History

20 Feb 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-20 00:15

Updated : 2025-02-20 00:15


NVD link : CVE-2024-37362

Mitre link : CVE-2024-37362

CVE.ORG link : CVE-2024-37362


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials