DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any interface. The vulnerability has been fixed in v2.10.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
The application does not verify the cryptographic signature of JWT (JSON Web Token) tokens, which means it accepts tokens crafted by an attacker without checking their authenticity. An attacker can independently generate a JWT token with arbitrary claims, including elevated privileges, and send it to the application. Because signature validation is missing, the application treats the forged token as valid and grants access to requested resources.
An unauthenticated attacker can gain unauthorized access to any interface of the DataEase application, leading to violations of confidentiality and integrity of processed data and system configuration.
DataEase should be updated to version v2.10.2 or later. The vendor informs that there are no known workarounds for this vulnerability — the only effective remediation is to update.
DataEase in versions prior to v2.10.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDataease
APPDataease< 2.10.2
Related vulnerabilities
SQL Injection w Dataease — niekontrolowany parametr tabeli w podglądzie danych
Dataease: RCE poprzez path traversal w parametrze IniFile sterownika JDBC
RCE w DataEase v1 poprzez komponenty konta użytkownika i hasła
DataEase – obejście uwierzytelnienia przez path traversal w TokenFilter
DataEase: hardkodowany sekret JWT umożliwia przejęcie usługi