CVE-2025-53004: Dataease Redshift Data Source JDBC Connection Parameters Bypass Vulnerability
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's Redshift Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has been patched in version 2.10.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53004?
CVE-2025-53004 has been designated a medium severity vulnerability due to the potential for SSL bypass.
How do I fix CVE-2025-53004?
To resolve CVE-2025-53004, upgrade to DataEase version 2.10.11 or later.
What parameters are involved in CVE-2025-53004?
CVE-2025-53004 involves the sslfactory and sslfactoryarg parameters which can trigger the bypass vulnerability.
What versions of DataEase are affected by CVE-2025-53004?
DataEase versions prior to 2.10.11 are affected by CVE-2025-53004.
What type of vulnerability is CVE-2025-53004?
CVE-2025-53004 is a bypass vulnerability that affects the SSL configuration in DataEase.