CVE-2025-27103

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

28 Mar 2025, 19:55

Type Values Removed Values Added
CPE cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
Summary
  • (es) DataEase es una herramienta de código abierto de inteligencia empresarial y visualización de datos. Antes de la versión 2.10.6, una omisión del parche para CVE-2024-55953 permitía a los usuarios autenticados leer y deserializar archivos arbitrarios mediante la conexión JDBC en segundo plano. La vulnerabilidad se ha corregido en la versión 2.10.6. No se conocen workarounds.
First Time Dataease
Dataease dataease
References () https://github.com/dataease/dataease/security/advisories/GHSA-v4gg-8rp3-ccjx - () https://github.com/dataease/dataease/security/advisories/GHSA-v4gg-8rp3-ccjx - Third Party Advisory, Exploit
CWE NVD-CWE-noinfo

13 Mar 2025, 20:15

Type Values Removed Values Added
References () https://github.com/dataease/dataease/security/advisories/GHSA-v4gg-8rp3-ccjx - () https://github.com/dataease/dataease/security/advisories/GHSA-v4gg-8rp3-ccjx -

13 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 17:15

Updated : 2025-03-28 19:55


NVD link : CVE-2025-27103

Mitre link : CVE-2025-27103

CVE.ORG link : CVE-2025-27103


JSON object : View

Products Affected

dataease

  • dataease
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-862

Missing Authorization

NVD-CWE-noinfo