PT-2021-11057 · Hitachi Vantara · Pentaho

Andrej Å Imko

·

Published

2021-01-29

·

Updated

2021-02-04

·

CVE-2020-24665

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Hitachi Vantara Pentaho versions 7.x through 8.x before 7.1.0.25 Hitachi Vantara Pentaho versions 8.x before 8.2.0.6 Hitachi Vantara Pentaho versions 8.3.0.0 before GA
Description: The Dashboard Editor in Hitachi Vantara Pentaho contains an XML Entity Expansion injection issue, allowing authenticated remote users to trigger a denial of service condition. The vulnerability is specifically related to the dashboardXml parameter.
Recommendations: For Hitachi Vantara Pentaho versions 7.x, update to version 7.1.0.25 or later. For Hitachi Vantara Pentaho versions 8.x before 8.2.0.6, update to version 8.2.0.6 or later. For Hitachi Vantara Pentaho versions 8.3.0.0 before GA, update to the GA version or later. As a temporary workaround, consider restricting access to the dashboardXml parameter to minimize the risk of exploitation.

Fix

XML Entity Expansion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24665

Affected Products

Pentaho