CVE-2025-27138: DataEase has an improper authentication vulnerability
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which may cause the risk of unauthorized access. The vulnerability has been fixed in v2.10.6. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.6
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27138?
CVE-2025-27138 has a moderate severity level due to the risk of unauthorized access.
How do I fix CVE-2025-27138?
To fix CVE-2025-27138, upgrade to DataEase version 2.10.6 or later.
What impact does CVE-2025-27138 have on my system?
CVE-2025-27138 can lead to unauthorized access to sensitive data if not mitigated.
Is my version vulnerable to CVE-2025-27138?
If you are using a version prior to DataEase 2.10.6, your system is vulnerable to CVE-2025-27138.
What components are affected by CVE-2025-27138?
CVE-2025-27138 affects the io.dataease.auth.filter.TokenFilter class in DataEase.