Lucene search

K

Dataease Security Vulnerabilities

cve
cve

CVE-2024-31441

DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in...

7.5CVSS

6.9AI Score

0.0004EPSS

2024-05-14 03:25 PM
10
cve
cve

CVE-2024-30269

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the /de2api/engine/getEngine;.js path via a browser reveals that the platform's database configuration is returned. The vulnerability has.....

5.3CVSS

6.4AI Score

0.0004EPSS

2024-04-08 03:15 PM
28
cve
cve

CVE-2024-23328

Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java. The...

9.1CVSS

9.4AI Score

0.0005EPSS

2024-02-29 01:44 AM
24
cve
cve

CVE-2023-28435

Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been....

6.5CVSS

6.4AI Score

0.001EPSS

2023-03-24 09:15 PM
17
2
cve
cve

CVE-2023-25807

DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when the user accesses the....

7.2CVSS

5.5AI Score

0.001EPSS

2023-02-28 04:15 PM
68
cve
cve

CVE-2023-40183

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to obtain user cookies. The program only uses the ImageIO.read() method to determine whether the file is an image file or not. There is no whitelisting....

7.5CVSS

5.2AI Score

0.001EPSS

2023-09-21 03:15 PM
15
cve
cve

CVE-2023-40771

SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist...

7.5CVSS

7.4AI Score

0.001EPSS

2023-09-01 04:15 PM
74
cve
cve

CVE-2022-34113

An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted...

9.8CVSS

9.5AI Score

0.003EPSS

2022-07-22 11:15 PM
386
3
cve
cve

CVE-2022-23331

In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator...

8.8CVSS

8.5AI Score

0.001EPSS

2022-02-08 01:15 PM
31
cve
cve

CVE-2023-37258

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known...

9.8CVSS

9.7AI Score

0.001EPSS

2023-07-25 08:15 PM
97
cve
cve

CVE-2023-37257

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known...

5.4CVSS

5.2AI Score

0.001EPSS

2023-07-25 08:15 PM
100
cve
cve

CVE-2023-34463

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known...

8.1CVSS

8.1AI Score

0.001EPSS

2023-06-26 09:15 PM
9
cve
cve

CVE-2023-35168

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed information includes md5 hashes of passwords,...

6.5CVSS

6.5AI Score

0.001EPSS

2023-06-26 09:15 PM
4
cve
cve

CVE-2023-35164

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixed in version...

6.5CVSS

6.4AI Score

0.001EPSS

2023-06-26 10:15 PM
8
cve
cve

CVE-2023-32310

DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or interfering with the...

8.1CVSS

7.9AI Score

0.001EPSS

2023-06-01 04:15 PM
15
cve
cve

CVE-2023-33963

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7. There are no known workarounds aside from...

9.8CVSS

9.7AI Score

0.002EPSS

2023-06-01 04:15 PM
12
cve
cve

CVE-2023-28637

DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may lead to remote code execution. This...

8.8CVSS

8.9AI Score

0.002EPSS

2023-03-28 09:15 PM
26
cve
cve

CVE-2023-28437

Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known...

9.8CVSS

9.9AI Score

0.001EPSS

2023-03-25 12:15 AM
17
cve
cve

CVE-2021-38239

SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to...

7.5CVSS

7.9AI Score

0.001EPSS

2023-02-15 10:15 PM
25
cve
cve

CVE-2022-39312

Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In...

9.8CVSS

9.6AI Score

0.001EPSS

2022-10-25 05:15 PM
52
6
cve
cve

CVE-2022-34115

DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter...

9.8CVSS

9.6AI Score

0.002EPSS

2022-07-22 11:15 PM
39
5
cve
cve

CVE-2022-34114

Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter...

8.8CVSS

9AI Score

0.001EPSS

2022-07-22 11:15 PM
48
5
cve
cve

CVE-2022-34112

An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the...

6.5CVSS

6.3AI Score

0.001EPSS

2022-07-22 11:15 PM
404
5