CVE-2024-37359
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918)
Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not validate the Host header of incoming HTTP/HTTPS requests.
By providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the attackers from accessing the URLs directly.
Leer descripción completaMostrar menos
The server can be used as a proxy to conduct port scanning of hosts in internal networks, use other URLs such as that can access documents on the system (using file://), or use other protocols such as gopher:// or tftp://, which may provide greater control over the contents of requests.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1090Proxycommand and control90 % - Impacto secundario
T1005Data from Local Systemcollection70 % - Impacto secundario
T1046Network Service Discoverydiscovery75 %
CWE-918 (SSRF) sin validación del Host header permite usar el servidor como proxy para escaneo de puertos internos (T1046), acceso a recursos locales (file://) y bypass de controles de acceso. AV:N/PR:N/UI:N confirma T1190.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-918
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-37359",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-37359",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-02-20T20:53:56.371593Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security.vulnerabilities@hitachivantara.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security.vulnerabilities@hitachivantara.com",
"affectedData": [
{
"vendor": "Hitachi Vantara",
"product": "Pentaho Data Integration & Analytics",
"versions": [
{
"status": "affected",
"version": "10.0",
"lessThan": "10.2.0.0",
"versionType": "maven"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Hitachi Vantara",
"product": "Pentaho Business Analytics Server",
"versions": [
{
"status": "affected",
"version": "1.0",
"lessThan": "9.3.0.9",
"versionType": "maven"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-02-19T23:15:10.330",
"references": [
{
"url": "https://support.pentaho.com/hc/en-us/articles/34296789835917--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Server-Side-Request-Forgery-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-37359",
"source": "security.vulnerabilities@hitachivantara.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security.vulnerabilities@hitachivantara.com",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918) \n\n\n\n \n\n\n\nHitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not validate the Host header of incoming HTTP/HTTPS requests.\n\n\n\n \n\n\n\nBy providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the attackers from accessing the URLs directly. The server can be used as a proxy to conduct port scanning of hosts in internal networks, use other URLs such as that can access documents on the system (using file://), or use other protocols such as gopher:// or tftp://, which may provide greater control over the contents of requests."
},
{
"lang": "es",
"value": "El servidor web recibe una URL o una solicitud similar de un componente ascendente y recupera el contenido de esta URL, pero no garantiza lo suficiente que la solicitud se envíe al destino esperado. (CWE-918) Las versiones de Hitachi Vantara Pentaho Business Analytics Server anteriores a 10.2.0.0 y 9.3.0.9, incluida la 8.3.x, no validan el encabezado Host de las solicitudes HTTP/HTTPS entrantes. Al proporcionar URL a puertos o hosts inesperados, los atacantes pueden hacer que parezca que el servidor está enviando la solicitud, posiblemente omitiendo los controles de acceso como los firewalls que impiden que los atacantes accedan a las URL directamente. El servidor se puede utilizar como proxy para realizar escaneos de puertos de hosts en redes internas, utilizar otras URL como las que pueden acceder a documentos en el sistema (utilizando file://) o utilizar otros protocolos como gopher:// o tftp://, que pueden proporcionar un mayor control sobre el contenido de las solicitudes."
}
],
"lastModified": "2026-06-17T07:38:13.127",
"sourceIdentifier": "security.vulnerabilities@hitachivantara.com"
}