Maven package
io.dataease/dataease-plugin-common
pkg:maven/io.dataease/dataease-plugin-common
Vulnerabilities (7)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-40771 | — | <= 1.18.9 | — | Sep 1, 2023 | SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function. | ||
| CVE-2023-32310 | — | < 1.18.7 | 1.18.7 | Jun 1, 2023 | DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or inte | ||
| CVE-2022-39312 | — | < 1.15.2 | 1.15.2 | Oct 25, 2022 | Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In ` | ||
| CVE-2022-34114 | — | < 1.11.2 | 1.11.2 | Jul 22, 2022 | Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId. | ||
| CVE-2022-34112 | — | < 1.11.2 | 1.11.2 | Jul 22, 2022 | An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator. | ||
| CVE-2022-34113 | — | < 1.11.2 | 1.11.2 | Jul 22, 2022 | An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin. | ||
| CVE-2022-34115 | — | < 1.11.2 | 1.11.2 | Jul 22, 2022 | DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. |
- CVE-2023-40771Sep 1, 2023affected <= 1.18.9
SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.
- CVE-2023-32310Jun 1, 2023affected < 1.18.7fixed 1.18.7
DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or inte
- CVE-2022-39312Oct 25, 2022affected < 1.15.2fixed 1.15.2
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In `
- CVE-2022-34114Jul 22, 2022affected < 1.11.2fixed 1.11.2
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
- CVE-2022-34112Jul 22, 2022affected < 1.11.2fixed 1.11.2
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
- CVE-2022-34113Jul 22, 2022affected < 1.11.2fixed 1.11.2
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
- CVE-2022-34115Jul 22, 2022affected < 1.11.2fixed 1.11.2
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.