Lucene search

K

Dataease Project Security Vulnerabilities

cve
cve

CVE-2022-34112

An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.

6.5CVSS

6.3AI Score

0.001EPSS

2022-07-22 11:15 PM
407
5
cve
cve

CVE-2022-34114

Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.

8.8CVSS

9AI Score

0.001EPSS

2022-07-22 11:15 PM
53
5
cve
cve

CVE-2022-34115

DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

9.8CVSS

9.6AI Score

0.002EPSS

2022-07-22 11:15 PM
42
5
cve
cve

CVE-2024-31441

DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in v1.18.19.

7.5CVSS

6.9AI Score

0.0004EPSS

2024-05-14 03:25 PM
17