PT-2025-27411 · Dataease · Dataease
For-A1Kaid
+1
·
Published
2025-06-30
·
Updated
2025-08-06
·
CVE-2025-53004
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DataEase versions prior to 2.10.11
Description:
DataEase is an open source business intelligence and data visualization tool. There is a bypass vulnerability in DataEase's Redshift Data Source JDBC Connection Parameters. The
sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has been patched in version 2.10.11.Recommendations:
For versions prior to 2.10.11, update to version 2.10.11 to resolve the issue. As a temporary workaround, consider restricting the use of the
sslfactory and sslfactoryarg parameters in the Redshift Data Source JDBC Connection Parameters until the update is applied.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dataease