Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to remote code execution. The Redshift JDBC driver execution flow reaches a method named getJdbcIniFile. The getJdbcIniFile method implements an aggressive automatic configuration file discovery mechanism. If not explicitly restricted, it searches for a file named rsjdbc.ini. In a JDBC URL context, users can explicitly specify the configuration file via URL parameters, which allows arbitrary files on the server to be loaded as JDBC configuration files. Within the Redshift JDBC driver properties, the parameter IniFile is explicitly supported and used to load an external configuration file. This vulnerability is fixed in 2.10.20.
The attacker manipulates the IniFile parameter in the JDBC URL, pointing to any file on the server as a Redshift JDBC driver configuration file. The getJdbcIniFile method in the Redshift JDBC driver implements an automatic configuration file discovery mechanism (rsjdbc.ini) which, if not explicitly restricted, allows loading external files. By embedding malicious JDBC properties in a controlled configuration file, the attacker can trigger arbitrary code execution on the server side.
An unauthenticated attacker can remotely execute arbitrary code on the server (RCE), resulting in complete system takeover and potential loss of confidentiality, integrity, and availability of data.
Dataease should be updated to version 2.10.20 or later, where the vulnerability has been patched. Details are available in the vendor's repository at: https://github.com/dataease/dataease/security/advisories/GHSA-jc9q-3jfw-mch4
Dataease in versions prior to 2.10.20
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDataease
APPDataease< 2.10.20
Related vulnerabilities
SQL Injection w Dataease — niekontrolowany parametr tabeli w podglądzie danych
RCE w DataEase v1 poprzez komponenty konta użytkownika i hasła
DataEase – obejście uwierzytelnienia przez path traversal w TokenFilter
DataEase: hardkodowany sekret JWT umożliwia przejęcie usługi
DataEase: brak weryfikacji podpisu JWT umożliwia dostęp do dowolnego interfejsu