VYPR
Critical severity9.1NVD Advisory· Published Feb 29, 2024· Updated Jun 17, 2026

CVE-2024-23328

CVE-2024-23328

Description

Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java. The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Dataease/Dataeasev53 versions
    < 1.18.15+ 2 more
    • (no CPE)range: < 1.18.15
    • (no CPE)range: >=1.18.15, >=2.3.0
    • cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*range: <1.18.15

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.