<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Hop</title>
  <link>https://cvedaily.com/pages/tags/apache-hop.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-hop.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Hop</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:08 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2024-24683 – Improper Input Validation vulnerability in Apache Hop Engine.This issue affects ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24683</guid>
    <pubDate>Tue, 19 Mar 2024 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-24683</strong></p>
  <p>Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0.  Users are recommended to upgrade to version 2.8.0, which fixes the issue.  When Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped. The variable not properly escaped is the "id", which is not directly…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24683">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
