Описание
DataEase's H2 datasource has a remote command execution risk
Impact
An attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string.
request message:
h2 data source connection string:
the content of poc.sql:
You can see that the file was created successfully in docker:
Affected versions: <= 2.10.0
Patches
The vulnerability has been fixed in v2.10.1.
Workarounds
It is recommended to upgrade the version to v2.10.1.
References
If you have any questions or comments about this advisory:
Open an issue in https://github.com/dataease/dataease Email us at wei@fit2cloud.com
Пакеты
io.dataease:common
<= 2.10.0
2.10.1
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
Связанные уязвимости
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3