CVE-2024-47074

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 11, 2024
Updated: Nov 12, 2024
CWE ID 502

Summary

CVE-2024-47074 is a newly disclosed vulnerability affecting DataEase, an open source data visualization analysis tool. The issue lies in the way the application handles custom JDBC connection parameters for PostgreSQL data sources. In the backend code, the PgConfiguration class fails to filter user input, allowing the concatenation of malicious parameters into the JDBC URL. If an attacker connects to a malicious PostgreSQL server with these manipulated parameters, they can exploit a deserialization vulnerability and gain system privileges. DataEase has released a fix for this issue in version 1.18.25.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share