Wersje Hitachi Vantara Pentaho Data Integration & Analytics poprzedzające 10.2.0.6 i 11.0.0.0, w tym 10.2.0.6 i 11.0.0.0, w tym linie 9.3.x i 8.3.x, ujawniają poświadczenia klastra Hadoop w postaci zwykłego tekstu poprzez Cluster Test API. Chociaż użytkownik nie powinien widzieć ich bezpośrednio, zagrożenie jest ograniczone faktem, że użytkownik może już wykorzystywać te poświadczenia do przesyłania zadań z tego samego konta za pośrednictwem backend API.
▸ Pokaż oryginał (EN)
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NHitachi Vantara Pentaho Data Integration And Analytics
APPHitachi8.39.3< 10.2.0.7< 11.0.0.0
Powiązane podatności
Hitachi Vantara Pentaho – RCE przez podatny sterownik JDBC H2
RCE przez brak restrykcji skryptów Groovy w raportach PRPT — Pentaho
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x an...
Hitachi Vantara Pentaho Data Integration & Analytics w wersjach poniżej 10.2.0.6 i 11.0.0.0, w tym 9.3.x i 8.3...
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x an...