CVE-2025-27103: Dataease Mysql JDBC Connection Parameters Not Being Verified Leads to Arbitrary File Read Vulnerability
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.6
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27103?
CVE-2025-27103 is classified as a high-severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2025-27103?
To mitigate CVE-2025-27103, upgrade to DataEase version 2.10.6 or later, which includes the necessary patch.
Who is affected by CVE-2025-27103?
CVE-2025-27103 affects all authenticated users of DataEase versions prior to 2.10.6.
What type of vulnerability is CVE-2025-27103?
CVE-2025-27103 is an information disclosure vulnerability that allows unauthorized file access through JDBC connections.
Is there an exploit available for CVE-2025-27103?
While specific exploit details are not publicly available, the vulnerability's nature suggests it can be exploited under certain conditions by authenticated users.