Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
Configurations
No configuration.
History
No history.
Information
Published : 2024-06-26 23:15
Updated : 2024-06-27 12:47
NVD link : CVE-2024-28982
Mitre link : CVE-2024-28982
CVE.ORG link : CVE-2024-28982
JSON object : View
Products Affected
No product.
CWE
CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')