SCA: security update for org.apache.hop:hop (GHSA-f6g6-pjgc-5cj5)

medium Tenable Cloud Security Plugin ID 414325

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before
2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes
links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not
properly escaped. The variable not properly escaped is the "id", which is not directly accessible by users
creating pipelines making the risk of exploiting this low. This issue only affects users using the Hop
Server component and does not directly affect the client. (CVE-2024-24683)

See Also

https://github.com/advisories/GHSA-f6g6-pjgc-5cj5

Plugin Details

Severity: Medium

ID: 414325

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2024-24683

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/19/2024

Vulnerability Publication Date: 3/19/2024

Reference Information

CVE: CVE-2024-24683

cwe: CWE-20