Back

CRITICAL

The Dataease datasource exists deserialization and arbitrary file read vulnerability

Published Feb 1, 2024

Description

Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 1, 2024
Updated Aug 28, 2024
Reserved Jan 15, 2024
CISA Vulnrichment
Updated Aug 28, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Feb 1, 2024
Updated Aug 28, 2024
Exploited since n/a
EUVD-2024-20843