CVE-2024-24683

CVE-2024-24683: Apache Hop Engine: ID isn't escaped when generating HTML

Vendor Apache Software Foundation
Product Apache Hop Engine
Weakness CWE-20 · Input validation
Published March 19, 2024
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped. The variable not properly escaped is the "id", which is not directly accessible by users creating pipelines making the risk of exploiting this low. This issue only affects users using the Hop Server component and does not directly affect the client.

Key dates

Disclosure timeline

March 19, 2024 CVE published
February 13, 2025 Record updated