Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47074

Опубликовано: 11 окт. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target to be connected. In backend/src/main/java/io/dataease/provider/datasource/JdbcProvider.java, PgConfiguration class don't filter any parameters, directly concat user input. So, if the attacker adds some parameters in JDBC url, and connect to evil PG server, the attacker can trigger the PG jdbc deserialization vulnerability, and eventually the attacker can execute through the deserialization vulnerability system commands and obtain server privileges. The vulnerability has been fixed in v1.18.25.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
Версия до 1.18.25 (исключая)

EPSS

Процентиль: 72%
0.00732
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

EPSS

Процентиль: 72%
0.00732
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502