CVE-2025-24907

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 35

Summary

CVE-2025-24907: Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.2, including 9.3.x and 8.3.x, contain a vulnerability where user input is not properly sanitized for file pathnames through the CGG Draw API. This issue, classified as CWE-35 ( Improper Output Sanitization), allows attackers to traverse the file system and access files or directories outside of the restricted directory by manipulating '.../...//' (doubled triple dot slash) sequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share