CVE-2023-35164: Unauthorized users can manipulate a dashboard created by an administrator in DataEase
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 1.18.8
Event History
Frequently Asked Questions
What is CVE-2023-35164?
CVE-2023-35164 is a vulnerability in DataEase, an open source data visualization analysis tool, that allows unauthorized users to manipulate a dashboard created by the administrator.
How severe is CVE-2023-35164?
CVE-2023-35164 has a severity rating of 6.5 (medium).
How can I fix CVE-2023-35164?
To fix CVE-2023-35164, you need to update DataEase to version 1.18.8 or higher, as this vulnerability has been fixed in that version.
What is the affected software version of CVE-2023-35164?
The affected software version of CVE-2023-35164 is up to (but not including) version 1.18.8 of DataEase.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-35164?
The Common Weakness Enumeration (CWE) ID for CVE-2023-35164 is CWE-862.