Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL to inject content into a dashboard when the CDE plugin is present.   
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: HITVAN

Published: 2023-04-11T15:45:03.366Z

Updated: 2024-08-03T01:14:03.359Z

Reserved: 2022-10-26T12:51:27.046Z

Link: CVE-2022-3695

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-11T16:15:07.050

Modified: 2023-04-20T20:46:03.467

Link: CVE-2022-3695

cve-icon Redhat

No data.