Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-24683— Apache Hop Engine: ID isn't escaped when generating HTML

EPSS 0.59% · P69
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-24683

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Hop Engine: ID isn't escaped when generating HTML
Source: NVD (National Vulnerability Database)
Vulnerability Description
Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped. The variable not properly escaped is the "id", which is not directly accessible by users creating pipelines making the risk of exploiting this low. This issue only affects users using the Hop Server component and does not directly affect the client.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache Hop Engine 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Hop Engine是美国阿帕奇(Apache)基金会的一个开源的数据集成、数据处理和工作流管理平台。 Apache Hop Engine 2.8.0 之前版本存在安全漏洞,该漏洞源于当 Hop Server 将链接写入 PrepareExecutionPipelineServlet 页面时,提供给用户的参数未正确转义。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache Hop Engine 0 ~ 2.8.0 -

II. Public POCs for CVE-2024-24683

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-24683

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-24683

No comments yet


Leave a comment