[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE Request - XXE in Pentaho Business Analytics 6.0.1.0.386
From:       Brendan Scarvell <bscarvell () iix ! net>
Date:       2016-04-22 1:32:26
Message-ID: CAOJmqsDC25MV1BMWeaQNfugjv0WbPRaXE3FTvWKvdWEK2Jfo5g () mail ! gmail ! com
[Download RAW message or body]


Hi there,

I've discovered an XXE vulnerability in Pentaho Business Analytics
Community Edition 6.0.1.0.386 due to Pentaho's xml parser not disabling the
parsing of external entities.

This issue has been reported to the vendor several times, who has refused
to fix it in the community edition unless an enterprise license is
purchased.  I've created a Github issue (
https://github.com/pentaho/data-access/issues/728) for someone in the
community to submit a patch.


Could a CVE ID please be assigned to this issue.


Thanks,

Brendan Scarvell


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic