CVE-2026-50124
- EPSS 0.32%
- Veröffentlicht 15.07.2026 19:38:14
- Zuletzt bearbeitet 17.07.2026 13:18:54
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses the zip: protocol, and executin...
CVE-2026-50030
- EPSS 0.27%
- Veröffentlicht 15.07.2026 19:24:51
- Zuletzt bearbeitet 18.07.2026 02:17:09
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/datasetData/previewSql, accepts PreviewSqlDTO.sql, PreviewSqlDTO.datasourceId, a...
CVE-2026-45419
- EPSS 0.31%
- Veröffentlicht 15.07.2026 19:21:46
- Zuletzt bearbeitet 18.07.2026 02:17:08
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker-controlled s...
CVE-2026-45417
- EPSS 0.23%
- Veröffentlicht 15.07.2026 19:20:16
- Zuletzt bearbeitet 16.07.2026 16:19:08
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into getTablesSql and execute the resulting SQL with executeQuery in io.dataease.dat...
- EPSS 0.4%
- Veröffentlicht 15.07.2026 19:19:10
- Zuletzt bearbeitet 16.07.2026 14:16:52
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.spr...
CVE-2026-50530
- EPSS 0.24%
- Veröffentlicht 07.07.2026 20:41:07
- Zuletzt bearbeitet 08.07.2026 15:07:37
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether tableId and field IDs in the reque...
CVE-2026-50529
- EPSS 0.29%
- Veröffentlicht 07.07.2026 20:39:23
- Zuletzt bearbeitet 08.07.2026 15:07:37
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket, allowing unauthenticated attackers wh...
CVE-2026-55647
- EPSS 0.27%
- Veröffentlicht 07.07.2026 20:37:54
- Zuletzt bearbeitet 08.07.2026 15:07:37
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue v-html without server-side HTML sanitization, allowing an authenticated user who can edit dashboard ...
CVE-2026-55635
- EPSS 0.27%
- Veröffentlicht 07.07.2026 20:35:43
- Zuletzt bearbeitet 09.07.2026 16:16:45
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL in Quota2SQLObj.getYWheres() without applying the SQL literal valida...
CVE-2026-57172
- EPSS 0.29%
- Veröffentlicht 07.07.2026 20:33:26
- Zuletzt bearbeitet 08.07.2026 15:07:37
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known ...