CVE-2025-24974

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are available.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

21 Mar 2025, 15:40

Type Values Removed Values Added
CPE cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
First Time Dataease
Dataease dataease
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/dataease/dataease/security/advisories/GHSA-wmfp-mjf3-57f5 - () https://github.com/dataease/dataease/security/advisories/GHSA-wmfp-mjf3-57f5 - Exploit, Vendor Advisory

13 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 17:15

Updated : 2025-03-21 15:40


NVD link : CVE-2025-24974

Mitre link : CVE-2025-24974


JSON object : View

Products Affected

dataease

  • dataease
CWE
CWE-862

Missing Authorization

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')