CVE-2025-49001: Dataease Authentication Bypass Vulnerability
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49001?
CVE-2025-49001 is considered a high-severity vulnerability due to the potential for unauthorized access using forged JWT tokens.
How do I fix CVE-2025-49001?
To fix CVE-2025-49001, upgrade DataEase to version 2.10.10 or later where the vulnerability has been patched.
What is affected by CVE-2025-49001?
Versions of DataEase prior to 2.10.10 are affected by CVE-2025-49001.
Can workarounds be applied for CVE-2025-49001?
No known workarounds are available for mitigating CVE-2025-49001 without upgrading the software.
What is the impact of exploiting CVE-2025-49001?
Exploiting CVE-2025-49001 allows an attacker to forge JWT tokens and potentially gain unauthorized access to sensitive data.