PT-2025-11213 · Dataease · Dataease

Racerz-Fighting

·

Published

2025-03-13

·

Updated

2025-03-21

·

CVE-2025-27138

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DataEase versions prior to 2.10.6
Description: The issue is related to a flaw in the authentication mechanism, specifically in the io.dataease.auth.filter.TokenFilter class, which may lead to unauthorized access.
Recommendations: For versions prior to 2.10.6, update to version 2.10.6 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application until the update can be applied.

Exploit

Fix

Incorrect Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27138
GHSA-533G-WHF8-Q637

Affected Products

Dataease