Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r5c8-8xvg-qm37

Опубликовано: 20 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)

 

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.

 

Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)

 

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.

 

Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.

EPSS

Процентиль: 27%
0.00095
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.3
nvd
12 месяцев назад

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)   Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.   Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.

CVSS3: 6.3
fstec
12 месяцев назад

Уязвимость программного средства для интеграции данных и аналитики Hitachi Vantara Pentaho Data Integration & Analytics, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю раскрыть конфиденциальную информацию

EPSS

Процентиль: 27%
0.00095
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-522