CVE-2024-23328

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Feb 29, 2024
CWE ID 502

Summary

CVE-2024-23328 is a deserialization vulnerability in the DataEase datasource, an open source data visualization analysis tool. This vulnerability allows attackers to execute arbitrary code by bypassing the blacklist of mysql jdbc attacks. They can exploit this vulnerability for deserialized execution or reading arbitrary files. The affected versions are patched in 1.18.15 and 2.3.0, and the risk score is rated at 65, with a base severity of CRITICAL. The exploitability score is 3.9, and it poses a high impact on both integrity and confidentiality. This vulnerability requires no privileges or user interaction, and it can be exploited over a network with low attack complexity. The availability impact is none, but organizations should promptly update to the patched versions to mitigate the potential danger it poses to their systems.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-23328 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions