Hitachi Vantara · Hitachi Vantara Pentaho · CVE-2020-24666
Name of the Vulnerable Software and Affected Versions:
Hitachi Vantara Pentaho versions 7.x through 8.x
Description:
The Analysis Report in Hitachi Vantara Pentaho contains a stored Cross-site scripting issue, allowing authenticated remote users to execute arbitrary JavaScript code. The vulnerability is specifically related to the `Display Name` parameter.
Recommendations:
For versions 7.x through 8.x, update to version 9.1.0.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `Display Name` parameter to minimize the risk of exploitation.