VYPR

Dataease

by Dataease

Source repositories

CVEs (92)

  • CVE-2025-62419HigOct 17, 2025
    risk 0.00cvss 7.5epss 0.00

    DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data source configuration handlers. In the DB2 data source handler, when the extraParams field is empty, the HOSTNAME,…

  • CVE-2025-58748CriSep 15, 2025
    risk 0.00cvss 9.8epss 0.01

    Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify that a provided JDBC URL starts with jdbc:h2. This lack of validation allows a crafted JDBC configuration that…

  • CVE-2025-58046CriSep 15, 2025
    risk 0.00cvss 9.8epss 0.01

    Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to remote code execution due to insufficient filtering in the getJdbc method of the io.dataease.datasource.type.Impala class.…

  • CVE-2025-58045CriSep 15, 2025
    risk 0.00cvss 9.8epss 0.01

    Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch introduced to mitigate DB2 JDBC deserialization remote code execution attacks only blacklisted the rmi parameter. The ldap parameter in the DB2 JDBC connection…

  • CVE-2025-48999HigJun 3, 2025
    risk 0.00cvss 8.8epss 0.08

    DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if…

  • CVE-2024-55953HigDec 18, 2024
    risk 0.00cvss 8.1epss 0.01

    DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through the background JDBC connection. When constructing the jdbc connection string, the parameters are not filtered. This vulnerability has been fixed in v1.18.27.…

  • CVE-2024-55952HigDec 18, 2024
    risk 0.00cvss 8.8epss 0.01

    DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JDBC connection. When constructing the jdbc connection string, the parameters are not filtered. Constructing the host as ip:5432/test/?socketFactory=org.springfra…

  • CVE-2024-52295CriNov 13, 2024
    risk 0.00cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has been fixed in v2.10.2.

  • CVE-2024-47074CriOct 11, 2024
    risk 0.00cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target to be connected. In backend/src/main/java/io/dataease/provider/datasource/JdbcPro…

  • CVE-2024-23328CriFeb 29, 2024
    risk 0.00cvss 9.1epss 0.01

    Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type…

  • CVE-2023-40183HigSep 21, 2023
    risk 0.00cvss 7.5epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to obtain user cookies. The program only uses the `ImageIO.read()` method to determine whether the file is an image file or not.…

  • CVE-2023-25807HigFeb 28, 2023
    risk 0.00cvss 7.2epss 0.01

    DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when…

Page 5 of 5