Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
History
Tue, 11 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HITVAN
Published:
Updated: 2025-02-11T14:40:28.479Z
Reserved: 2022-10-26T12:55:14.327Z
Link: CVE-2022-43771
Updated: 2024-08-03T13:40:06.238Z
Status : Modified
Published: 2023-04-03T19:15:06.913
Modified: 2024-11-21T07:27:12.223
Link: CVE-2022-43771
No data.
OpenCVE Enrichment
No data.
Weaknesses