Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-58748

Опубликовано: 15 сент. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify that a provided JDBC URL starts with jdbc:h2. This lack of validation allows a crafted JDBC configuration that substitutes the Amazon Redshift driver and leverages the socketFactory and socketFactoryArg parameters to invoke org.springframework.context.support.FileSystemXmlApplicationContext or ClassPathXmlApplicationContext with an attacker‑controlled remote XML resource, resulting in remote code execution. Versions up to and including 2.10.12 are affected. The issue is fixed in version 2.10.13. Updating to version 2.10.13 or later is the recommended remediation. No known workarounds exist.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
Версия до 2.10.13 (исключая)

EPSS

Процентиль: 74%
0.00794
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

EPSS

Процентиль: 74%
0.00794
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502