CVE-2024-47073
CVSS 3.1 Score 0.0 of 10 (low)
Details
Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 347
Summary
CVE-2024-47073 is a vulnerability affecting DataEase, an open source data visualization analysis tool. In exploited versions of the software, attackers can bypass authentication by forging JWT tokens due to the absence of signature verification. This issue grants unauthorized access to any interface, making it a significant security concern. Affected users are urged to upgrade to version 2.10.2, which contains the necessary patch. Unfortunately, there are currently no reported workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Data Ease
Affected Vendors
- Dataease