CRITICAL🇵🇱 Wersja polska

CVE-2024-47073

CVSS 9.3v4.0pub. 2024-11-07upd. 2025-02-20

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any interface. The vulnerability has been fixed in v2.10.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

🤖 AI Analysis
How it works

The application does not verify the cryptographic signature of JWT (JSON Web Token) tokens, which means it accepts tokens crafted by an attacker without checking their authenticity. An attacker can independently generate a JWT token with arbitrary claims, including elevated privileges, and send it to the application. Because signature validation is missing, the application treats the forged token as valid and grants access to requested resources.

Impact

An unauthenticated attacker can gain unauthorized access to any interface of the DataEase application, leading to violations of confidentiality and integrity of processed data and system configuration.

Mitigation & patch

DataEase should be updated to version v2.10.2 or later. The vendor informs that there are no known workarounds for this vulnerability — the only effective remediation is to update.

Who is affected

DataEase in versions prior to v2.10.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dataease

    APP
    Dataease
    < 2.10.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-32137CRITICAL9.3PL ✓same product

SQL Injection w Dataease — niekontrolowany parametr tabeli w podglądzie danych

CVE-2026-32140CRITICAL9.3PL ✓same product

Dataease: RCE poprzez path traversal w parametrze IniFile sterownika JDBC

CVE-2024-57707CRITICAL9.8PL ✓same product

RCE w DataEase v1 poprzez komponenty konta użytkownika i hasła

CVE-2024-56511CRITICAL9.3PL ✓same product

DataEase – obejście uwierzytelnienia przez path traversal w TokenFilter

CVE-2024-52295CRITICAL9.3PL ✓same product

DataEase: hardkodowany sekret JWT umożliwia przejęcie usługi