Skip to content

Commit

Permalink
1 changes (1 new | 0 updated):
Browse files Browse the repository at this point in the history
      - 1 new CVEs:  CVE-2023-5617
      - 0 updated CVEs:
  • Loading branch information
cvelistV5 Github Action committed Feb 28, 2024
1 parent 839e33d commit 5663a86
Show file tree
Hide file tree
Showing 3 changed files with 143 additions and 5 deletions.
124 changes: 124 additions & 0 deletions cves/2023/5xxx/CVE-2023-5617.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,124 @@
{
"dataType": "CVE_RECORD",
"dataVersion": "5.0",
"cveMetadata": {
"cveId": "CVE-2023-5617",
"assignerOrgId": "dce6e192-ff49-4263-9134-f0beccb9bc13",
"state": "PUBLISHED",
"assignerShortName": "HITVAN",
"dateReserved": "2023-10-17T15:42:11.661Z",
"datePublished": "2024-02-28T22:30:40.128Z",
"dateUpdated": "2024-02-28T22:30:40.128Z"
},
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pentaho Data Integration & Analytics",
"vendor": "Hitachi Vantara",
"versions": [
{
"lessThan": "9.3.0.6",
"status": "affected",
"version": "1.0",
"versionType": "maven"
},
{
"lessThan": "10.1.0.0",
"status": "affected",
"version": "9.4.0.0",
"versionType": "maven"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Hitachi Group Member"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\n\n<p>Hitachi Vantara Pentaho Data Integration &amp; Analytics versions before 10.1.0.0 and 9.3.0.6, including&nbsp;<span style=\"background-color: var(--wht);\">9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.</span></p>\n\n"
}
],
"value": "\nHitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.\n\n\n\n"
}
],
"impacts": [
{
"capecId": "CAPEC-170",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-170 Web Application Fingerprinting"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-550",
"description": "CWE-550: Server-generated Error Message Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"orgId": "dce6e192-ff49-4263-9134-f0beccb9bc13",
"shortName": "HITVAN",
"dateUpdated": "2024-02-28T22:30:40.128Z"
},
"references": [
{
"url": "https://support.pentaho.com/hc/en-us/articles/24313358254861--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Server-generated-Error-Message-Containing-Sensitive-Information-Versions-before-10-1-0-0-and-9-3-0-6-including-all-versions-before-10-0-x-Impacted-CVE-2023-5617"
}
],
"source": {
"discovery": "INTERNAL"
},
"title": "Hitachi Vantara Pentaho Data Integration & Analytics - Server-generated Error Message Containing Sensitive Information",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
}
}
10 changes: 5 additions & 5 deletions cves/delta.json
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
{
"fetchTime": "2024-02-28T22:15:24.852Z",
"fetchTime": "2024-02-28T22:35:07.715Z",
"numberOfChanges": 1,
"new": [
{
"cveId": "CVE-2024-22532",
"cveOrgLink": "https://www.cve.org/CVERecord?id=CVE-2024-22532",
"githubLink": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/22xxx/CVE-2024-22532.json",
"dateUpdated": "2024-02-28T22:12:48.430622"
"cveId": "CVE-2023-5617",
"cveOrgLink": "https://www.cve.org/CVERecord?id=CVE-2023-5617",
"githubLink": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/5xxx/CVE-2023-5617.json",
"dateUpdated": "2024-02-28T22:30:40.128Z"
}
],
"updated": [],
Expand Down
14 changes: 14 additions & 0 deletions cves/deltaLog.json
Original file line number Diff line number Diff line change
@@ -1,4 +1,18 @@
[
{
"fetchTime": "2024-02-28T22:35:07.715Z",
"numberOfChanges": 1,
"new": [
{
"cveId": "CVE-2023-5617",
"cveOrgLink": "https://www.cve.org/CVERecord?id=CVE-2023-5617",
"githubLink": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/5xxx/CVE-2023-5617.json",
"dateUpdated": "2024-02-28T22:30:40.128Z"
}
],
"updated": [],
"error": []
},
{
"fetchTime": "2024-02-28T22:15:24.852Z",
"numberOfChanges": 1,
Expand Down

0 comments on commit 5663a86

Please sign in to comment.