CVE-2024-28982

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
Configurations

No configuration.

History

No history.

Information

Published : 2024-06-26 23:15

Updated : 2024-06-27 12:47


NVD link : CVE-2024-28982

Mitre link : CVE-2024-28982

CVE.ORG link : CVE-2024-28982


JSON object : View

Products Affected

No product.

CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')