CVSS 3.1 Score 9.1 of 10 (high)


Published Feb 29, 2024
CWE ID 502


CVE-2024-23328 is a deserialization vulnerability in the DataEase datasource, an open source data visualization analysis tool. This vulnerability allows attackers to execute arbitrary code by bypassing the blacklist of mysql jdbc attacks. They can exploit this vulnerability for deserialized execution or reading arbitrary files. The affected versions are patched in 1.18.15 and 2.3.0, and the risk score is rated at 65, with a base severity of CRITICAL. The exploitability score is 3.9, and it poses a high impact on both integrity and confidentiality. This vulnerability requires no privileges or user interaction, and it can be exploited over a network with low attack complexity. The availability impact is none, but organizations should promptly update to the patched versions to mitigate the potential danger it poses to their systems.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-23328 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options