VYPR

Maven package

io.dataease/dataease-plugin-common

pkg:maven/io.dataease/dataease-plugin-common

Vulnerabilities (7)

  • CVE-2023-40771Sep 1, 2023
    affected <= 1.18.9

    SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

  • CVE-2023-32310Jun 1, 2023
    affected < 1.18.7fixed 1.18.7

    DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or inte

  • CVE-2022-39312Oct 25, 2022
    affected < 1.15.2fixed 1.15.2

    Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In `

  • CVE-2022-34114Jul 22, 2022
    affected < 1.11.2fixed 1.11.2

    Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.

  • CVE-2022-34112Jul 22, 2022
    affected < 1.11.2fixed 1.11.2

    An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.

  • CVE-2022-34113Jul 22, 2022
    affected < 1.11.2fixed 1.11.2

    An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.

  • CVE-2022-34115Jul 22, 2022
    affected < 1.11.2fixed 1.11.2

    DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.