Dataease

Dataease

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 26.17%
  • Veröffentlicht 07.11.2024 18:15:17
  • Zuletzt bearbeitet 20.02.2025 16:20:40

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which the...

  • EPSS 0.73%
  • Veröffentlicht 11.10.2024 15:15:05
  • Zuletzt bearbeitet 12.11.2024 19:52:38

DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target to be connected. In backend/src/main/java/io/dataea...

Exploit
  • EPSS 14.86%
  • Veröffentlicht 23.09.2024 16:15:06
  • Zuletzt bearbeitet 07.10.2024 17:20:10

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 23.09.2024 16:15:06
  • Zuletzt bearbeitet 27.09.2024 16:35:25

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An attacker can construct a payload to implement intran...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 14.05.2024 15:25:18
  • Zuletzt bearbeitet 12.02.2025 17:49:35

DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vu...

  • EPSS 92.32%
  • Veröffentlicht 08.04.2024 15:15:07
  • Zuletzt bearbeitet 12.02.2025 17:50:06

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform's database...

Exploit
  • EPSS 0.7%
  • Veröffentlicht 29.02.2024 01:44:08
  • Zuletzt bearbeitet 08.01.2025 18:52:16

Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/ja...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 21.09.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:18:57

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to obtain user cookies. The program only uses the `ImageIO.read()` method to determine whether the file...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 01.09.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 08:20:06

SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 25.07.2023 20:15:13
  • Zuletzt bearbeitet 21.11.2024 08:11:19

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds.