CVE-2024-23328

Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.
Configurations

No configuration.

History

21 Nov 2024, 08:57

Type Values Removed Values Added
Summary
  • (es) Dataease es una herramienta de análisis de visualización de datos de código abierto. Existe una vulnerabilidad de deserialización en la fuente de datos de DataEase, que puede explotarse para ejecutar código arbitrario. La ubicación del código de vulnerabilidad es `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` La lista negra de ataques jdbc de mysql se puede omitir y los atacantes pueden explotarla aún más para deserializarla. ejecución o lectura de archivos arbitrarios. Esta vulnerabilidad está parcheada en 1.18.15 y 2.3.0.
References () https://github.com/dataease/dataease/commit/4128adf5fc4592b55fa1722a53b178967545d46a - () https://github.com/dataease/dataease/commit/4128adf5fc4592b55fa1722a53b178967545d46a -
References () https://github.com/dataease/dataease/commit/bb540e6dc83df106ac3253f331066129a7487d1a - () https://github.com/dataease/dataease/commit/bb540e6dc83df106ac3253f331066129a7487d1a -
References () https://github.com/dataease/dataease/security/advisories/GHSA-8x8q-p622-jf25 - () https://github.com/dataease/dataease/security/advisories/GHSA-8x8q-p622-jf25 -

29 Feb 2024, 01:44

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:44

Updated : 2024-11-21 08:57


NVD link : CVE-2024-23328

Mitre link : CVE-2024-23328

CVE.ORG link : CVE-2024-23328


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data