CVE-2025-32966

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

24 Jun 2025, 16:36

Type Values Removed Values Added
References () https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7 - () https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7 - Exploit, Vendor Advisory
First Time Dataease
Dataease dataease
CPE cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

23 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-23 16:15

Updated : 2025-06-24 16:36


NVD link : CVE-2025-32966

Mitre link : CVE-2025-32966


JSON object : View

Products Affected

dataease

  • dataease
CWE
CWE-290

Authentication Bypass by Spoofing