cve/2022/CVE-2022-43769.md

18 lines
937 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-43769](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43769)
![](https://img.shields.io/static/v1?label=Product&message=Pentaho%20Business%20Analytics%20Server&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.0%3C%209.3.0.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-74%20Improper%20Neutralization%20of%20Special%20Elements%20in%20Output%20Used%20by%20a%20Downstream%20Component%20('Injection')&color=brighgreen)
### Description
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. 
### POC
#### Reference
- http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html
#### Github
No PoCs found on GitHub currently.