Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
References
Configurations
No configuration.
History
15 Dec 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-15 23:15
Updated : 2025-12-16 14:10
NVD link : CVE-2025-9121
Mitre link : CVE-2025-9121
CVE.ORG link : CVE-2025-9121
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data
