← Back to CVE List

CVE-2024-23328

Published: 2024-02-29T01:44Z
Last Modified: 2025-01-08T18:52Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt