PT-2025-45169 · Dataease · Dataease

CVE-2025-64163

·

Published

2025-11-05

·

Updated

2025-11-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DataEase versions 2.10.14 and below
Description DataEase is a data visualization analysis tool. Versions 2.10.14 and below lack proper protection for the dns:// protocol, leading to a Server-Side Request Forgery (SSRF) condition. The vendor implemented a blacklist to filter ldap:// and ldaps://, but failed to include dns:// in the filtering mechanism. This allows attackers to potentially make requests to internal resources.
Recommendations Update to version 2.10.15 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64163
GHSA-8397-V66P-539M

Affected Products

Dataease