The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section. Remediated in >= 8.3.0.9, >= 9.0.0.1, and >= 9.1.0.0 GA.
References
Link | Resource |
---|---|
http://www.hitachi.com/hirt/hitachi-sec/2020/601.html | Vendor Advisory |
https://www.accenture.com | Not Applicable |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-01-29 11:15
Updated : 2021-02-04 08:24
NVD link : CVE-2020-24669
Mitre link : CVE-2020-24669
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
hitachi
- vantara_pentaho