PT-2025-27411 · Dataease · Dataease

For-A1Kaid

+1

·

Published

2025-06-30

·

Updated

2025-08-06

·

CVE-2025-53004

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DataEase versions prior to 2.10.11
Description: DataEase is an open source business intelligence and data visualization tool. There is a bypass vulnerability in DataEase's Redshift Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has been patched in version 2.10.11.
Recommendations: For versions prior to 2.10.11, update to version 2.10.11 to resolve the issue. As a temporary workaround, consider restricting the use of the sslfactory and sslfactoryarg parameters in the Redshift Data Source JDBC Connection Parameters until the update is applied.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-53004
GHSA-MFG2-QR5C-99PP

Affected Products

Dataease