U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-24683

Change History

New CVE Received from Apache Software Foundation 3/19/2024 5:15:06 AM

Action Type Old Value New Value
Added Description

								
							
							
						
Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0.

Users are recommended to upgrade to version 2.8.0, which fixes the issue.

When Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped.
The variable not properly escaped is the "id", which is not directly accessible by users creating pipelines making the risk of exploiting this low.

This issue only affects users using the Hop Server component and does not directly affect the client.
Added CWE

								
							
							
						
Apache Software Foundation CWE-20
Added Reference

								
							
							
						
Apache Software Foundation https://lists.apache.org/thread/ts203zssv1n9qth1wdlhk2bhos3vcq6t [No types assigned]