Dataease

Dataease

62 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.15%
  • Veröffentlicht 07.02.2025 16:15:38
  • Zuletzt bearbeitet 28.03.2025 17:24:50

An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 10.01.2025 16:15:29
  • Zuletzt bearbeitet 20.02.2025 16:26:58

DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause the risk of unauthorized access. In the io.dataease....

Exploit
  • EPSS 1.89%
  • Veröffentlicht 18.12.2024 19:15:12
  • Zuletzt bearbeitet 20.02.2025 16:25:07

DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through the background JDBC connection. When constructing the jdbc connection string, the parameters are not filtered. This vulnerability...

Exploit
  • EPSS 1.32%
  • Veröffentlicht 18.12.2024 19:15:11
  • Zuletzt bearbeitet 20.02.2025 16:22:50

DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JDBC connection. When constructing the jdbc connection string, the parameters are not filtered. Constructing the host as ip:5432/tes...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 13.11.2024 16:15:19
  • Zuletzt bearbeitet 20.02.2025 16:21:26

DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has been fixed ...

Exploit
  • EPSS 49.74%
  • Veröffentlicht 07.11.2024 18:15:17
  • Zuletzt bearbeitet 20.02.2025 16:20:40

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which the...

  • EPSS 0.99%
  • Veröffentlicht 11.10.2024 15:15:05
  • Zuletzt bearbeitet 12.11.2024 19:52:38

DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target to be connected. In backend/src/main/java/io/dataea...

Exploit
  • EPSS 18.93%
  • Veröffentlicht 23.09.2024 16:15:06
  • Zuletzt bearbeitet 07.10.2024 17:20:10

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 23.09.2024 16:15:06
  • Zuletzt bearbeitet 27.09.2024 16:35:25

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An attacker can construct a payload to implement intran...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 14.05.2024 15:25:18
  • Zuletzt bearbeitet 12.02.2025 17:49:35

DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vu...