CVE-2024-47074
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-47074 is a newly disclosed vulnerability affecting DataEase, an open source data visualization analysis tool. The issue lies in the way the application handles custom JDBC connection parameters for PostgreSQL data sources. In the backend code, the PgConfiguration class fails to filter user input, allowing the concatenation of malicious parameters into the JDBC URL. If an attacker connects to a malicious PostgreSQL server with these manipulated parameters, they can exploit a deserialization vulnerability and gain system privileges. DataEase has released a fix for this issue in version 1.18.25.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Data Ease
Affected Vendors
- Dataease