CVE-2025-64163: DataEase's DB2 is vulnerable to SSRF
Published Nov 5, 2025
·Updated
DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps://. However, omission of protection for the dns:// protocol results in an SSRF vulnerability. This issue is fixed in version 2.10.15.
Affected Software
3 affected components
Dataease DataEase<=2.10.14
Dataease DB2
Dataease DataEase<2.10.15
Remediation
Event History
Nov 5, 2025
CVE Published
via MITRE·11:52 PM
Data Sourced
via MITRE·11:52 PM
DescriptionWeakness
Nov 6, 2025
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64163?
CVE-2025-64163 is classified as a critical SSRF (Server-Side Request Forgery) vulnerability.
2
How do I fix CVE-2025-64163?
To fix CVE-2025-64163, upgrade DataEase to version 2.10.15 or later.
3
What versions of DataEase are affected by CVE-2025-64163?
CVE-2025-64163 affects DataEase versions 2.10.14 and below.
4
What type of vulnerability is CVE-2025-64163?
CVE-2025-64163 is an SSRF vulnerability due to insufficient input validation on the dns:// protocol.
5
Is there a mitigation for CVE-2025-64163?
The recommended mitigation for CVE-2025-64163 is to update to version 2.10.15 or later as it contains the fix.