CVE-2024-23328

CVSS 3.1 Score 9.1 of 10 (high)

Attack Complexity low
Confidentiality high
Integrity high
Availability none
Scope unchanged
Privileges Required none

Details

Published Feb 29, 2024
Updated: Jan 8, 2025
CWE ID 502

Summary

CVE-2024-23328 is a deserialization vulnerability affecting the DataEase open source data visualization analysis tool. This issue lies within the DataEase datasource and can be exploited by attackers to execute arbitrary code. The vulnerability can be found in the `Mysql.java` file located at `core/core-backend/src/main/java/io/dataease/datasource/type/`. By bypassing the blacklist of mysql jdbc attacks, attackers can further exploit this vulnerability for deserialized execution or reading arbitrary files. The vulnerability is resolved in versions 1.18.15 and 2.3.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share