The product transmits or stores authentication...
Moderate severity
Unreviewed
Published
Feb 20, 2025
to the GitHub Advisory Database
•
Updated Feb 20, 2025
Description
Published by the National Vulnerability Database
Feb 20, 2025
Published to the GitHub Advisory Database
Feb 20, 2025
Last updated
Feb 20, 2025
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.
Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.
References