PT-2025-37721 · Amazon+3 · Amazon Redshift+3
Jilinxiangyun-Lab
+1
·
Published
2025-09-15
·
Updated
2025-09-20
·
CVE-2025-58748
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dataease versions prior to 2.10.13
Description
Dataease is an open source data analytics and visualization platform. The H2 data source implementation (H2.java) lacks validation to ensure that a provided JDBC URL begins with
jdbc:h2. This allows a crafted JDBC configuration to substitute the Amazon Redshift driver and utilize the socketFactory and socketFactoryArg parameters to invoke org.springframework.context.support.FileSystemXmlApplicationContext or ClassPathXmlApplicationContext with a remote XML resource controlled by an attacker, potentially leading to remote code execution.Recommendations
Update to Dataease version 2.10.13 or later.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Redshift
Dataease
H2
Spring Framework