CVE-2025-32966

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

24 Jun 2025, 16:36

Type Values Removed Values Added
CPE cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
References () https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7 - () https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Dataease dataease
Dataease

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) DataEase es una herramienta de inteligencia empresarial (BI) de código abierto alternativa a Tableau. Antes de la versión 2.10.8, los usuarios autenticados podían completar RCE mediante el enlace JDBC del backend. Este problema se ha corregido en la versión 2.10.8.

23 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-23 16:15

Updated : 2025-06-24 16:36


NVD link : CVE-2025-32966

Mitre link : CVE-2025-32966

CVE.ORG link : CVE-2025-32966


JSON object : View

Products Affected

dataease

  • dataease
CWE
CWE-290

Authentication Bypass by Spoofing