Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
1.0 (maven) before 10.2.0.4
affected
Description
Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
1.0 (maven) before 10.2.0.4
Credits
Hitachi Group Member
References
support.pentaho.com/...efore-10-2-0-4-Impacted-CVE-2025-9121
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.