Arbitrary File Reading Vulnerability in DataEase
CVE-2024-31441
7.5HIGH
Key Information:
- Vendor
- Dataease
- Status
- Dataease
- Vendor
- CVE Published:
- 14 May 2024
Summary
DataEase, an open-source data visualization analysis tool, is susceptible to a vulnerability that allows for arbitrary file reading due to inadequate restrictions on connection parameters for the ClickHouse data source. Malicious actors can exploit this flaw by injecting specific harmful parameters into the connection, potentially leading to unauthorized access to sensitive files on the server. The vulnerability has been addressed in version 1.18.19, making it crucial for users to update their installations to mitigate any risks associated with this issue. More details can be found in the security advisory at the official GitHub repository.
Affected Version(s)
dataease < 1.18.19
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved