CVE-2024-24683

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/03/2024
Last modified:
15/07/2025

Description

Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0.<br /> <br /> Users are recommended to upgrade to version 2.8.0, which fixes the issue.<br /> <br /> When Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped.<br /> The variable not properly escaped is the "id", which is not directly accessible by users creating pipelines making the risk of exploiting this low.<br /> <br /> This issue only affects users using the Hop Server component and does not directly affect the client.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:hop_engine:*:*:*:*:*:*:*:* 2.8.0 (excluding)