peter bassill · operator
$ cve CVE-2024-56511 JSON

CVE-2024-56511

9.8
CRITICAL · CVSS 3.1 · EPSS 44.5% (pctl 99)

Patch early

EPSS 44.5% — above the 10% action threshold.

Description

DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause the risk of unauthorized access. In the io.dataease.auth.filter.TokenFilter class, ”request.getRequestURI“ is used to obtain the request URL, and it is passed to the "WhitelistUtils.match" method to determine whether the URL request is an interface that does not require authentication. The "match" method filters semicolons, but this is not enough. When users set "server.servlet.context-path" when deploying products, there is still a risk of being bypassed, which can be bypassed by any whitelist prefix /geo/../context-path/. The vulnerability has been fixed in v2.10.4.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS44.46% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-289
On CISA KEVno
Public exploitnone known
Published2025-01-10
Last modified2026-06-17

Affected (1)

VendorProduct
dataeasedataease

References

→ the Explorer  ·  watch your stack  ·  NVD