Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.
Metrics
Affected Vendors & Products
References
History
Wed, 27 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitachi
Hitachi vantara Pentaho Data Integration And Analytics |
|
| Vendors & Products |
Hitachi
Hitachi vantara Pentaho Data Integration And Analytics |
Wed, 27 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API. | |
| Title | Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HITVAN
Published: 2026-05-27T02:51:31.793Z
Updated: 2026-05-27T18:00:39.061Z
Reserved: 2026-02-09T15:09:09.473Z
Link: CVE-2026-2255
Updated: 2026-05-27T18:00:35.379Z
Status : Awaiting Analysis
Published: 2026-05-27T04:16:26.833
Modified: 2026-05-27T19:55:50.070
Link: CVE-2026-2255
No data.