Dataease Visualization Platform Vulnerability Impacts Security Features
CVE-2025-58045
What is CVE-2025-58045?
Dataease, an open source data analytics and visualization platform, is susceptible to a serious vulnerability where the DB2 JDBC connection string allows for server-side request forgery (SSRF). In versions up to 2.10.12, only the 'rmi' parameter was blacklisted, leaving the 'ldap' parameter vulnerable to exploitation. Although more recent Java versions have disabled ldap deserialization (autoDeserialize) by default, the SSRF risk persists in the affected versions. Users are advised to upgrade to Dataease version 2.10.13 or later to mitigate this risk, as no known workarounds are available other than updating.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dataease < 2.10.13
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
