Dataease Visualization Platform Vulnerability Impacts Security Features
CVE-2025-58045
7.1HIGH
What is CVE-2025-58045?
Dataease, an open source data analytics and visualization platform, is susceptible to a serious vulnerability where the DB2 JDBC connection string allows for server-side request forgery (SSRF). In versions up to 2.10.12, only the 'rmi' parameter was blacklisted, leaving the 'ldap' parameter vulnerable to exploitation. Although more recent Java versions have disabled ldap deserialization (autoDeserialize) by default, the SSRF risk persists in the affected versions. Users are advised to upgrade to Dataease version 2.10.13 or later to mitigate this risk, as no known workarounds are available other than updating.
Affected Version(s)
dataease < 2.10.13