Dataease
by Dataease
Source repositories
CVEs (92)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37258 | Hig | 0.57 | 8.8 | 0.01 | Jul 25, 2023 | DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds. | ||
| CVE-2022-39312 | Cri | 0.57 | 9.8 | 0.02 | Oct 25, 2022 | Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In… | ||
| CVE-2022-34115 | Cri | 0.57 | 9.8 | 0.01 | Jul 22, 2022 | DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. | ||
| CVE-2022-34114 | Hig | 0.57 | 8.8 | 0.01 | Jul 22, 2022 | Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId. | ||
| CVE-2022-23331 | Hig | 0.57 | 8.8 | 0.01 | Feb 8, 2022 | In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password. | ||
| CVE-2023-34463 | Hig | 0.53 | 8.1 | 0.01 | Jun 26, 2023 | DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade.… | ||
| CVE-2023-28637 | Hig | 0.52 | 8.0 | 0.01 | Mar 28, 2023 | DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may lead to remote code… | ||
| CVE-2026-40901 | Hig | 0.50 | 8.8 | 0.01 | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserialization gadget chain. Quartz 2.3.2, also bundled in the… | ||
| CVE-2026-40900 | Hig | 0.50 | 8.8 | 0.00 | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL is wrapped in a subquery without validation that the input is a single… | ||
| CVE-2026-33207 | Hig | 0.50 | 8.8 | 0.00 | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method in CalciteProvider.java incorporates the tableName parameter directly… | ||
| CVE-2026-33121 | Hig | 0.50 | 8.8 | 0.00 | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The deTableName field from the Base64-encoded datasource configuration is used to construct a DDL… | ||
| CVE-2026-33084 | Hig | 0.50 | 8.8 | 0.00 | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. The DatasetDataManage service layer directly transfers the user-supplied… | ||
| CVE-2026-33083 | Hig | 0.50 | 8.8 | 0.00 | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoints including /de2api/datasetData/enumValueDs and… | ||
| CVE-2026-32140 | Hig | 0.50 | 8.8 | 0.01 | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to… | ||
| CVE-2026-32137 | Hig | 0.50 | 8.8 | 0.00 | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string,… | ||
| CVE-2024-46985 | Hig | 0.49 | 7.5 | 0.01 | Sep 23, 2024 | DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An attacker can construct a payload to implement intranet detection and file… | ||
| CVE-2024-31441 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2024 | DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in… | ||
| CVE-2023-40771 | Hig | 0.49 | 7.5 | 0.01 | Sep 1, 2023 | SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function. | ||
| CVE-2021-38239 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10. | ||
| CVE-2026-32939 | Hig | 0.46 | 8.1 | 0.00 | Mar 20, 2026 | DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handling between the JDBC URL validation logic and the H2 JDBC engine's internal parsing. DataEase uses String.toUpperCase() without specifying an explicit Locale,… |
- risk 0.57cvss 8.8epss 0.01
DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds.
- risk 0.57cvss 9.8epss 0.02
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In…
- risk 0.57cvss 9.8epss 0.01
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
- risk 0.57cvss 8.8epss 0.01
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
- risk 0.57cvss 8.8epss 0.01
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.
- risk 0.53cvss 8.1epss 0.01
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade.…
- risk 0.52cvss 8.0epss 0.01
DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may lead to remote code…
- risk 0.50cvss 8.8epss 0.01
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserialization gadget chain. Quartz 2.3.2, also bundled in the…
- risk 0.50cvss 8.8epss 0.00
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL is wrapped in a subquery without validation that the input is a single…
- risk 0.50cvss 8.8epss 0.00
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method in CalciteProvider.java incorporates the tableName parameter directly…
- risk 0.50cvss 8.8epss 0.00
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The deTableName field from the Base64-encoded datasource configuration is used to construct a DDL…
- risk 0.50cvss 8.8epss 0.00
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. The DatasetDataManage service layer directly transfers the user-supplied…
- risk 0.50cvss 8.8epss 0.00
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoints including /de2api/datasetData/enumValueDs and…
- risk 0.50cvss 8.8epss 0.01
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to…
- risk 0.50cvss 8.8epss 0.00
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string,…
- risk 0.49cvss 7.5epss 0.01
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An attacker can construct a payload to implement intranet detection and file…
- risk 0.49cvss 7.5epss 0.01
DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in…
- risk 0.49cvss 7.5epss 0.01
SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.
- risk 0.49cvss 7.5epss 0.01
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
- risk 0.46cvss 8.1epss 0.00
DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handling between the JDBC URL validation logic and the H2 JDBC engine's internal parsing. DataEase uses String.toUpperCase() without specifying an explicit Locale,…
Page 2 of 5