CVE-2026-53751
- EPSS 0.4%
- Veröffentlicht 07.07.2026 20:31:12
- Zuletzt bearbeitet 08.07.2026 15:07:37
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with special Unicode characters whose case-conversion behavior differs between DataEase validation and H2 par...
CVE-2026-53730
- EPSS 0.24%
- Veröffentlicht 07.07.2026 20:29:19
- Zuletzt bearbeitet 09.07.2026 16:16:43
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any authenticated user to specify datasourceId=-1,...
CVE-2026-55633
- EPSS 0.5%
- Veröffentlicht 07.07.2026 20:27:28
- Zuletzt bearbeitet 08.07.2026 15:16:29
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an authenticated attacker to upload a zip archive disguised with a .ttf extension through FontManage.saveFi...
CVE-2026-55631
- EPSS 0.31%
- Veröffentlicht 07.07.2026 20:24:56
- Zuletzt bearbeitet 08.07.2026 15:07:37
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName when creating a font record; when the record is later deleted, the backend c...
CVE-2026-53729
- EPSS 0.39%
- Veröffentlicht 07.07.2026 20:23:08
- Zuletzt bearbeitet 08.07.2026 15:16:29
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or generate download links (/export...
CVE-2026-8724
- EPSS 0.39%
- Veröffentlicht 17.05.2026 00:30:10
- Zuletzt bearbeitet 19.05.2026 19:04:13
A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remote...
CVE-2026-40901
- EPSS 0.63%
- Veröffentlicht 16.04.2026 20:57:45
- Zuletzt bearbeitet 20.04.2026 16:46:41
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserialization gadget chain. Quartz 2.3...
CVE-2026-40900
- EPSS 0.34%
- Veröffentlicht 16.04.2026 20:53:27
- Zuletzt bearbeitet 20.04.2026 16:46:14
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL is wrapped in a subquery without validation t...
CVE-2026-40899
- EPSS 0.39%
- Veröffentlicht 16.04.2026 20:16:38
- Zuletzt bearbeitet 20.04.2026 16:42:13
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto...
CVE-2026-33207
- EPSS 0.35%
- Veröffentlicht 16.04.2026 19:37:36
- Zuletzt bearbeitet 20.04.2026 16:41:20
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method in CalciteProvider.java incorporates the tab...