CVE-2024-52295

CVSS 3.1 Score 0.0 of 10 (low)

Details

Published Nov 13, 2024
CWE ID 798

Summary

CVE-2024-52295 is a vulnerability affecting the open source data visualization analysis tool, DataEase, prior to version 2.10.2. This issue enables attackers to forge jerwey tokens (JWT) and gain unauthorized access to services. The cause of the vulnerability lies in the hardcoding of the JWT secret and the UID and OID in the code. Successful exploitation of this weakness can lead to takeover of affected services. Fortunately, version 2.10.2 of DataEase includes a fix for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share