CVE-2025-24907
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 35
Summary
CVE-2025-24907: Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.2, including 9.3.x and 8.3.x, contain a vulnerability where user input is not properly sanitized for file pathnames through the CGG Draw API. This issue, classified as CWE-35 ( Improper Output Sanitization), allows attackers to traverse the file system and access files or directories outside of the restricted directory by manipulating '.../...//' (doubled triple dot slash) sequences.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Hitachi Vantara