PT-2025-27411 · Dataease · Dataease
For-A1Kaid
+1
·
Publicado
2025-06-30
·
Atualizado
2025-08-06
·
CVE-2025-53004
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DataEase versions prior to 2.10.11
Description:
DataEase is an open source business intelligence and data visualization tool. There is a bypass vulnerability in DataEase's Redshift Data Source JDBC Connection Parameters. The
sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has been patched in version 2.10.11.Recommendations:
For versions prior to 2.10.11, update to version 2.10.11 to resolve the issue. As a temporary workaround, consider restricting the use of the
sslfactory and sslfactoryarg parameters in the Redshift Data Source JDBC Connection Parameters until the update is applied.Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dataease