CVE-2024-23328
The Dataease datasource exists deserialization and arbitrary file read vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.
Dataease es una herramienta de análisis de visualización de datos de código abierto. Existe una vulnerabilidad de deserialización en la fuente de datos de DataEase, que puede explotarse para ejecutar código arbitrario. La ubicación del código de vulnerabilidad es `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` La lista negra de ataques jdbc de mysql se puede omitir y los atacantes pueden explotarla aún más para deserializarla. ejecución o lectura de archivos arbitrarios. Esta vulnerabilidad está parcheada en 1.18.15 y 2.3.0.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-01-15 CVE Reserved
- 2024-02-01 CVE Published
- 2024-02-29 EPSS Updated
- 2024-08-28 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/dataease/dataease/commit/4128adf5fc4592b55fa1722a53b178967545d46a | X_refsource_misc | |
https://github.com/dataease/dataease/commit/bb540e6dc83df106ac3253f331066129a7487d1a | X_refsource_misc | |
https://github.com/dataease/dataease/security/advisories/GHSA-8x8q-p622-jf25 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dataease Search vendor "Dataease" | Dataease Search vendor "Dataease" for product "Dataease" | < 1.18.15 Search vendor "Dataease" for product "Dataease" and version " < 1.18.15" | en |
Affected
| ||||||
Dataease Search vendor "Dataease" | Dataease Search vendor "Dataease" for product "Dataease" | >= 2.0.0 < 2.3.0 Search vendor "Dataease" for product "Dataease" and version " >= 2.0.0 < 2.3.0" | en |
Affected
|