CVE-2024-24683

MEDIUM

Apache Hop Engine <2.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped. The variable not properly escaped is the "id", which is not directly accessible by users creating pipelines making the risk of exploiting this low. This issue only affects users using the Hop Server component and does not directly affect the client.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/03/18/1
Issue Tracking, Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/ts203zssv1n9qth1wdlhk2bhos3vcq6t

Scores

CVSS v3 6.5
EPSS 0.0059
EPSS Percentile 69.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
apache/hop_engine < 2.8.0
org.apache.hop/hop 0 - 2.8.0Maven
Published Mar 19, 2024
Tracked Since Feb 18, 2026