PT-2025-11213 · Dataease · Dataease
Racerz-Fighting
·
Published
2025-03-13
·
Updated
2025-03-21
·
CVE-2025-27138
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DataEase versions prior to 2.10.6
Description:
The issue is related to a flaw in the authentication mechanism, specifically in the
io.dataease.auth.filter.TokenFilter class, which may lead to unauthorized access.Recommendations:
For versions prior to 2.10.6, update to version 2.10.6 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive areas of the application until the update can be applied.
Exploit
Fix
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dataease