CVE-2023-40772
- EPSS -
- Veröffentlicht 14.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.
CVE-2026-90529
- EPSS 0.2%
- Veröffentlicht 13.09.2026 14:45:11
- Zuletzt bearbeitet 15.09.2026 15:17:28
A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such ma...
CVE-2026-82879
- EPSS 0.22%
- Veröffentlicht 31.08.2026 10:51:05
- Zuletzt bearbeitet 08.09.2026 20:18:59
DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another (ShareTicketManage.validateTicket / POST...
CVE-2026-82878
- EPSS 0.2%
- Veröffentlicht 31.08.2026 10:51:04
- Zuletzt bearbeitet 08.09.2026 20:18:59
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite ...
CVE-2026-45532
- EPSS 0.38%
- Veröffentlicht 18.08.2026 12:53:14
- Zuletzt bearbeitet 18.09.2026 20:09:01
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during str...
CVE-2026-49867
- EPSS 0.27%
- Veröffentlicht 15.07.2026 20:17:12
- Zuletzt bearbeitet 18.07.2026 02:17:09
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit TemplateManageRequest.staticResource through POST /de2api/templateManage/save or DataVisualizationSer...
CVE-2026-46684
- EPSS 0.19%
- Veröffentlicht 15.07.2026 19:41:15
- Zuletzt bearbeitet 17.07.2026 19:17:15
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before u...
CVE-2026-45320
- EPSS 0.27%
- Veröffentlicht 15.07.2026 19:40:28
- Zuletzt bearbeitet 17.07.2026 20:17:16
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transFilter(), whose final branch returns raw user input for non-in and non-between ...
CVE-2026-45535
- EPSS 0.25%
- Veröffentlicht 15.07.2026 19:39:47
- Zuletzt bearbeitet 16.07.2026 14:16:52
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries such as ${var} and SqlparserUtils.handleVariableDefaultValue() inserts them with...
CVE-2026-45533
- EPSS 0.31%
- Veröffentlicht 15.07.2026 19:39:08
- Zuletzt bearbeitet 17.07.2026 13:18:49
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bulk delete API endpoint and pass attacker-controlled identifiers to ExportCente...