CVE-2025-58748

Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify that a provided JDBC URL starts with jdbc:h2. This lack of validation allows a crafted JDBC configuration that substitutes the Amazon Redshift driver and leverages the socketFactory and socketFactoryArg parameters to invoke org.springframework.context.support.FileSystemXmlApplicationContext or ClassPathXmlApplicationContext with an attacker‑controlled remote XML resource, resulting in remote code execution. Versions up to and including 2.10.12 are affected. The issue is fixed in version 2.10.13. Updating to version 2.10.13 or later is the recommended remediation. No known workarounds exist.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

19 Sep 2025, 19:31

Type Values Removed Values Added
References () https://github.com/dataease/dataease/commit/23a45e72a7abc37d5680b0a7cf691b8df378d4ef - () https://github.com/dataease/dataease/commit/23a45e72a7abc37d5680b0a7cf691b8df378d4ef - Patch
References () https://github.com/dataease/dataease/security/advisories/GHSA-23qw-9qrh-9rr8 - () https://github.com/dataease/dataease/security/advisories/GHSA-23qw-9qrh-9rr8 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
First Time Dataease
Dataease dataease

15 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-15 17:15

Updated : 2025-09-19 19:31


NVD link : CVE-2025-58748

Mitre link : CVE-2025-58748

CVE.ORG link : CVE-2025-58748


JSON object : View

Products Affected

dataease

  • dataease
CWE
CWE-502

Deserialization of Untrusted Data