CVE-2025-53005: Dataease PostgreSQL Data Source JDBC Connection Parameters Bypass Vulnerability
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has been patched in version 2.10.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53005?
CVE-2025-53005 is considered a medium-severity vulnerability due to its potential to bypass security controls in JDBC connection parameters.
How do I fix CVE-2025-53005?
You can fix CVE-2025-53005 by upgrading DataEase to version 2.10.11 or later, which mitigates the bypass vulnerability.
What software is affected by CVE-2025-53005?
CVE-2025-53005 affects DataEase versions prior to 2.10.11.
Can CVE-2025-53005 lead to data exposure?
Yes, CVE-2025-53005 can potentially lead to data exposure by allowing an attacker to bypass security measures.
Is CVE-2025-53005 exploitable remotely?
Yes, CVE-2025-53005 can be exploited remotely if the vulnerable DataEase instance is exposed to the internet.