← Back to CVE List

CVE-2020-24669

Published: 2021-01-29T19:15Z
Last Modified: 2024-11-21T05:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section. Remediated in >= 8.3.0.9, >= 9.0.0.1, and >= 9.1.0.0 GA. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt