DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality. The difference lies in that "sslfactory" and related parameters need to be triggered after establishing the connection. Other similar parameters include "sslhostnameverifier", "sslpasswordcallback", and "authenticationPluginClassName". This issue has been patched in 2.10.11.
References
Link | Resource |
---|---|
https://github.com/dataease/dataease/security/advisories/GHSA-q726-5pr9-x7gm | Exploit Vendor Advisory |
Configurations
History
10 Jul 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-02 15:15
Updated : 2025-07-10 15:16
NVD link : CVE-2025-53006
Mitre link : CVE-2025-53006
CVE.ORG link : CVE-2025-53006
JSON object : View
Products Affected
dataease
- dataease
CWE
CWE-153
Improper Neutralization of Substitution Characters