CRITICAL
The Dataease datasource exists deserialization and arbitrary file read vulnerability
Published Feb 1, 2024
9.1
CRITICALCVSS 3.1
EPSS 1.21%
Description
Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.
Affected products
-
- Version < 1.18.15StatusaffectedConstraints-
- Version >= 2.0.0, < 2.3.0StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<1.18.15
- Version 2.0.0StatusaffectedConstraints<2.3.0
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-20843 Advisory
- https://github.com/dataease/dataease/commit/4128adf5fc4592b55fa1722a53b178967545d46a x_refsource_MISCPatch
- https://github.com/dataease/dataease/commit/bb540e6dc83df106ac3253f331066129a7487d1a x_refsource_MISCPatch
- https://github.com/dataease/dataease/security/advisories/GHSA-8x8q-p622-jf25 x_refsource_CONFIRMExploitVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-20843 | Advisory | |
| https://github.com/dataease/dataease/commit/4128adf5fc4592b55fa1722a53b178967545d46a | x_refsource_MISCPatch | |
| https://github.com/dataease/dataease/commit/bb540e6dc83df106ac3253f331066129a7487d1a | x_refsource_MISCPatch | |
| https://github.com/dataease/dataease/security/advisories/GHSA-8x8q-p622-jf25 | x_refsource_CONFIRMExploitVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 1, 2024
Updated Aug 28, 2024
Reserved Jan 15, 2024
Link CVE-2024-23328
CISA Vulnrichment
Updated Aug 28, 2024
ENISA EUVD
EUVD-2024-20843 Assigner GitHub_M
Published Feb 1, 2024
Updated Aug 28, 2024
Exploited since n/a
Link EUVD-2024-20843