Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmp2-cvfp-6gr9

Опубликовано: 27 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.

EPSS

Процентиль: 6%
0.00165
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 4.3
nvd
2 месяца назад

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.

CVSS3: 4.3
fstec
2 месяца назад

Уязвимость программного средства для интеграции данных и аналитики Hitachi Vantara Pentaho Data Integration & Analytics, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 6%
0.00165
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-522