Jacopo Taccucci

1 exploit Active since Feb 2025
CVE-2024-57971 WRITEUP CRITICAL WRITEUP
KNOWAGE < 8.1.30 - Resource Injection via JNDI Name Manipulation
DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.
CVSS 9.1