First published: Wed Apr 23 2025(Updated: )
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dataease | <2.10.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32966 has a high severity rating due to the potential for remote code execution.
To fix CVE-2025-32966, upgrade DataEase to version 2.10.8 or later.
Authenticated users of DataEase versions prior to 2.10.8 are affected by CVE-2025-32966.
CVE-2025-32966 allows authenticated users to execute remote code through the backend JDBC link.
CVE-2025-32966 was patched in version 2.10.8 of DataEase.