2025-03-02 03:03:52 +00:00

60 lines
3.7 KiB
JSON

{
"id": "CVE-2024-37360",
"sourceIdentifier": "security.vulnerabilities@hitachivantara.com",
"published": "2025-02-19T23:15:10.537",
"lastModified": "2025-02-19T23:15:10.537",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') \n\n\n\n\u00a0\n\n\n\nThe software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)\n\n\n\n\u00a0\n\n\n\nHitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.0 and 9.3.0.9, including 8.3.x, allow a malicious URL to inject content into the Analyzer plugin interface.\n\n\n\n\u00a0\n\n\n\n\nOnce the malicious script is injected, the attacker can perform a variety of malicious activities. The attacker could transfer private information, such as cookies that may include session information, from the victim's machine to the attacker. The attacker could send malicious requests to a web site on behalf of the victim, which could be especially dangerous to the site if the victim has administrator privileges to manage that site."
},
{
"lang": "es",
"value": "Hitachi Vantara Pentaho Business Analytics Server - Neutralizaci\u00f3n incorrecta de la entrada durante la generaci\u00f3n de p\u00e1ginas web ('Cross-site Scripting') El software no neutraliza o neutraliza incorrectamente la entrada controlable por el usuario antes de colocarla en la salida que se utiliza como una p\u00e1gina web que se ofrece a otros usuarios. (CWE-79) Hitachi Vantara Pentaho Business Analytics Server anterior a las versiones 10.2.0.0 y 9.3.0.9, incluida la 8.3.x, permite que una URL maliciosa inyecte contenido en la interfaz del complemento Analyzer. Una vez que se inyecta el script malicioso, el atacante puede realizar una variedad de actividades maliciosas. El atacante podr\u00eda transferir informaci\u00f3n privada, como cookies que pueden incluir informaci\u00f3n de sesi\u00f3n, desde la m\u00e1quina de la v\u00edctima al atacante. El atacante podr\u00eda enviar solicitudes maliciosas a un sitio web en nombre de la v\u00edctima, lo que podr\u00eda ser especialmente peligroso para el sitio si la v\u00edctima tiene privilegios de administrador para administrar ese sitio."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security.vulnerabilities@hitachivantara.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N",
"baseScore": 4.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 0.7,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "security.vulnerabilities@hitachivantara.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://support.pentaho.com/hc/en-us/articles/34298351866893--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-CVE-2024-37360",
"source": "security.vulnerabilities@hitachivantara.com"
}
]
}