CVE-2025-9121

Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-15 23:15

Updated : 2025-12-16 14:10


NVD link : CVE-2025-9121

Mitre link : CVE-2025-9121

CVE.ORG link : CVE-2025-9121


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data