First published: Thu May 01 2025(Updated: )
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.9.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dataease | <2.10.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46566 has been classified as a critical vulnerability due to its potential for allowing remote code execution.
To remediate CVE-2025-46566, upgrade DataEase to version 2.10.9 or later.
Authenticated users of DataEase versions prior to 2.10.9 are affected by CVE-2025-46566.
CVE-2025-46566 is a remote code execution vulnerability.
CVE-2025-46566 was published in 2025.