Dataease
by Dataease
Source repositories
CVEs (72)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32310 | 0.00 | — | 0.01 | Jun 1, 2023 | DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or… | |||
| CVE-2023-28637 | 0.00 | — | 0.01 | Mar 28, 2023 | DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may lead to remote code… | |||
| CVE-2023-28437 | 0.00 | — | 0.01 | Mar 24, 2023 | Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds. | |||
| CVE-2023-28435 | 0.00 | — | 0.00 | Mar 24, 2023 | Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These… | |||
| CVE-2023-25807 | 0.00 | — | 0.01 | Feb 28, 2023 | DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when… | |||
| CVE-2021-38239 | 0.00 | — | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10. | |||
| CVE-2022-39312 | 0.00 | — | 0.01 | Oct 25, 2022 | Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In… | |||
| CVE-2022-34112 | 0.00 | — | 0.01 | Jul 22, 2022 | An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator. | |||
| CVE-2022-34114 | 0.00 | — | 0.01 | Jul 22, 2022 | Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId. | |||
| CVE-2022-34113 | 0.00 | — | 0.01 | Jul 22, 2022 | An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin. | |||
| CVE-2022-34115 | 0.00 | — | 0.01 | Jul 22, 2022 | DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. | |||
| CVE-2022-23331 | 0.00 | — | 0.01 | Feb 8, 2022 | In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password. |
- CVE-2023-32310Jun 1, 2023risk 0.00cvss —epss 0.01
DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or…
- CVE-2023-28637Mar 28, 2023risk 0.00cvss —epss 0.01
DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may lead to remote code…
- CVE-2023-28437Mar 24, 2023risk 0.00cvss —epss 0.01
Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.
- CVE-2023-28435Mar 24, 2023risk 0.00cvss —epss 0.00
Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These…
- CVE-2023-25807Feb 28, 2023risk 0.00cvss —epss 0.01
DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when…
- CVE-2021-38239Feb 15, 2023risk 0.00cvss —epss 0.01
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
- CVE-2022-39312Oct 25, 2022risk 0.00cvss —epss 0.01
Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In…
- CVE-2022-34112Jul 22, 2022risk 0.00cvss —epss 0.01
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
- CVE-2022-34114Jul 22, 2022risk 0.00cvss —epss 0.01
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
- CVE-2022-34113Jul 22, 2022risk 0.00cvss —epss 0.01
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
- CVE-2022-34115Jul 22, 2022risk 0.00cvss —epss 0.01
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
- CVE-2022-23331Feb 8, 2022risk 0.00cvss —epss 0.01
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.
Page 4 of 4