From 2097a5dd91a2b94f80d2777145fdc084510d4f9b Mon Sep 17 00:00:00 2001 From: MostInterestingBotInTheWorld <98333686+MostInterestingBotInTheWorld@users.noreply.github.com> Date: Thu, 13 Apr 2023 13:06:44 -0400 Subject: [PATCH] Enhancement: cves/2022/CVE-2022-43769.yaml by md --- cves/2022/CVE-2022-43769.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cves/2022/CVE-2022-43769.yaml b/cves/2022/CVE-2022-43769.yaml index 38e5551059..05c769a8f6 100644 --- a/cves/2022/CVE-2022-43769.yaml +++ b/cves/2022/CVE-2022-43769.yaml @@ -5,7 +5,7 @@ info: author: dwbzn severity: critical description: | - Hitachi Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x, is susceptible to remote code execution via server-side template injection. Certain web services can set property values which contain Spring templates that are interpreted downstream, thereby potentially enabling an attacker to execute malware, obtain sensitive information, modify data, and/or perform unauthorized functions without entering necessary credentials. + Hitachi Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x, is susceptible to remote code execution via server-side template injection. Certain web services can set property values which contain Spring templates that are interpreted downstream, thereby potentially enabling an attacker to execute malware, obtain sensitive information, modify data, and/or perform unauthorized operations without entering necessary credentials. reference: - https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769- - https://nvd.nist.gov/vuln/detail/CVE-2022-43769