PT-2025-27634 · Dataease · Dataease

Unam4

·

Published

2025-06-26

·

Updated

2025-07-02

·

CVE-2025-53006

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DataEase versions prior to 2.10.11
Description: DataEase is an open source business intelligence and data visualization tool. The issue lies in parameters like sslfactory and sslfactoryarg, which have similar functionality to socketfactory and socketfactoryarg, but need to be triggered after establishing the connection. Other similar parameters include sslhostnameverifier, sslpasswordcallback, and authenticationPluginClassName.
Recommendations: For versions prior to 2.10.11, update to version 2.10.11 to resolve the issue. As a temporary workaround, consider restricting the use of parameters like sslfactory and sslfactoryarg until the update is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-08272
CVE-2025-53006
GHSA-Q726-5PR9-X7GM

Affected Products

Dataease