CVE Vulnerabilities

CVE-2021-45446

Exposure of Information Through Directory Listing

Published: Nov 02, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in

Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources located inside the directory.

Weakness

A directory listing is inappropriately exposed, yielding potentially sensitive information to attackers.

Affected Software

Name Vendor Start Version End Version
Vantara_pentaho Hitachi 8.3.0.0 (including) 8.3.0.25 (excluding)
Vantara_pentaho Hitachi 9.2.0.0 (including) 9.2.0.2 (excluding)

Potential Mitigations

References