PT-2026-60278 · Dataease · Dataease
CVE-2026-46684
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
DataEase versions prior to 2.10.23
Description
In the enterprise token handling of this data visualization and analysis tool, the
TokenFilter#doFilter() function passes X-DE-TOKEN values to TokenUtils.validate(). This process only verifies the presence and length of the token before the userBOByToken(token) function employs JWT.decode() without performing signature verification. This allows forged tokens with arbitrary uid and oid values to be accepted when licenseValid is set to true. JWT (JSON Web Token) is a compact, URL-safe means of representing claims to be transferred between two parties.Recommendations
Update to version 2.10.23.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dataease