CVE-2024-57971

DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.
Configurations

No configuration.

History

21 Mar 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) DataSourceResource.java en el soporte de API de SpagoBI en Knowage Server en KNOWAGE antes de 8.1.30 no garantiza que java:comp/env/jdbc/ aparezca al comienzo de un nombre JNDI.
References
  • () https://github.com/darumaseye/CVEs/blob/ec2de9f7ecffde466e687745bfdfc672e86241d7/CVE-2024-57971.md -

16 Feb 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-16 04:15

Updated : 2025-03-21 14:15


NVD link : CVE-2024-57971

Mitre link : CVE-2024-57971

CVE.ORG link : CVE-2024-57971


JSON object : View

Products Affected

No product.

CWE
CWE-99

Improper Control of Resource Identifiers ('Resource Injection')