{"api_version":"1","generated_at":"2026-07-23T22:43:36+00:00","cve":"CVE-2020-24669","urls":{"html":"https://cve.report/CVE-2020-24669","api":"https://cve.report/api/cve/CVE-2020-24669.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-24669","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-24669"},"summary":{"title":"CVE-2020-24669","description":"The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section. Remediated in >= 8.3.0.9, >= 9.0.0.1, and >= 9.1.0.0 GA.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-01-29 19:15:00","updated_at":"2021-02-04 16:24:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://www.accenture.com","name":"https://www.accenture.com","refsource":"MISC","tags":["Not Applicable"],"title":"Accenture | Let there be change","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.hitachi.com/hirt/hitachi-sec/2020/601.html","name":"http://www.hitachi.com/hirt/hitachi-sec/2020/601.html","refsource":"MISC","tags":["Vendor Advisory"],"title":"hitachi-sec-2020-601Multiple Vulnerabilities in Pentaho : Hitachi Incident Response Team : Hitachi","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-24669","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-24669","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"24669","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"vantara_pentaho","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"24669","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hitachi","cpe5":"vantara_pentaho","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-24669","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section. Remediated in >= 8.3.0.9, >= 9.0.0.1, and >= 9.1.0.0 GA."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.accenture.com","refsource":"MISC","name":"https://www.accenture.com"},{"refsource":"MISC","name":"http://www.hitachi.com/hirt/hitachi-sec/2020/601.html","url":"http://www.hitachi.com/hirt/hitachi-sec/2020/601.html"}]}},"nvd":{"publishedDate":"2021-01-29 19:15:00","lastModifiedDate":"2021-02-04 16:24:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hitachi:vantara_pentaho:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0","versionEndExcluding":"8.3.0.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hitachi:vantara_pentaho:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.0.0.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"24669","Ordinal":"186079","Title":"CVE-2020-24669","CVE":"CVE-2020-24669","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"24669","Ordinal":"1","NoteData":"The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report Description' field in 'About this Report' section. Remediated in >= 8.3.0.9, >= 9.0.0.1, and >= 9.1.0.0 GA.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"24669","Ordinal":"2","NoteData":"2021-01-29","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"24669","Ordinal":"3","NoteData":"2021-01-29","Type":"Other","Title":"Modified"}]}}}