VYPR

Maven package

io.dataease/dataease-plugin-common

pkg:maven/io.dataease/dataease-plugin-common

Vulnerabilities (7)

  • CVE-2023-40771HigSep 1, 2023
    affected <= 1.18.9

    SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

  • CVE-2023-32310HigJun 1, 2023
    affected < 1.18.7fixed 1.18.7

    DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or inte

  • CVE-2022-39312CriOct 25, 2022
    affected < 1.15.2fixed 1.15.2

    Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In `

  • CVE-2022-34115CriJul 22, 2022
    affected < 1.11.2fixed 1.11.2

    DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

  • CVE-2022-34114HigJul 22, 2022
    affected < 1.11.2fixed 1.11.2

    Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.

  • CVE-2022-34113CriJul 22, 2022
    affected < 1.11.2fixed 1.11.2

    An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.

  • CVE-2022-34112MedJul 22, 2022
    affected < 1.11.2fixed 1.11.2

    An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.