PT-2025-27634 · Dataease · Dataease

Unam4

·

Publicado

2025-06-26

·

Atualizado

2025-07-02

·

CVE-2025-53006

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DataEase versions prior to 2.10.11
Description: DataEase is an open source business intelligence and data visualization tool. The issue lies in parameters like sslfactory and sslfactoryarg, which have similar functionality to socketfactory and socketfactoryarg, but need to be triggered after establishing the connection. Other similar parameters include sslhostnameverifier, sslpasswordcallback, and authenticationPluginClassName.
Recommendations: For versions prior to 2.10.11, update to version 2.10.11 to resolve the issue. As a temporary workaround, consider restricting the use of parameters like sslfactory and sslfactoryarg until the update is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-08272
CVE-2025-53006
GHSA-Q726-5PR9-X7GM

Produtos afetados

Dataease