CVE-2025-24974

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are available.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

21 Mar 2025, 15:40

Type Values Removed Values Added
First Time Dataease dataease
Dataease
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
References () https://github.com/dataease/dataease/security/advisories/GHSA-wmfp-mjf3-57f5 - () https://github.com/dataease/dataease/security/advisories/GHSA-wmfp-mjf3-57f5 - Exploit, Vendor Advisory
Summary
  • (es) DataEase es una herramienta de código abierto de inteligencia empresarial y visualización de datos. Antes de la versión 2.10.6, los usuarios autenticados podían leer y deserializar archivos arbitrarios mediante la conexión JDBC en segundo plano. La vulnerabilidad se ha corregido en la versión 2.10.6. No se conocen workarounds.

13 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 17:15

Updated : 2025-03-21 15:40


NVD link : CVE-2025-24974

Mitre link : CVE-2025-24974

CVE.ORG link : CVE-2025-24974


JSON object : View

Products Affected

dataease

  • dataease
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-862

Missing Authorization