PT-2025-27411 · Dataease · Dataease

For-A1Kaid

+1

·

Publicado

2025-06-30

·

Atualizado

2025-08-06

·

CVE-2025-53004

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DataEase versions prior to 2.10.11
Description: DataEase is an open source business intelligence and data visualization tool. There is a bypass vulnerability in DataEase's Redshift Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has been patched in version 2.10.11.
Recommendations: For versions prior to 2.10.11, update to version 2.10.11 to resolve the issue. As a temporary workaround, consider restricting the use of the sslfactory and sslfactoryarg parameters in the Redshift Data Source JDBC Connection Parameters until the update is applied.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-53004
GHSA-MFG2-QR5C-99PP

Produtos afetados

Dataease