GHSA-p37q-jm8v-rgqfHighCVSS 7.7
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0,...
🔗 CVE IDs covered (1)
📋 Description
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.
🔗 References (3)
- https://nvd.nist.gov/vuln/detail/CVE-2026-2253
- https://support.pentaho.com/hc/en-us/articles/45677548193933--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Improper-Restriction-of-XML-External-Entity-Reference-Versions-before-10-2-0-7-and-11-0-0-0-Impacted-CVE-2026-2253
- https://github.com/advisories/GHSA-p37q-jm8v-rgqf