HIGH🇵🇱 Wersja polska

CVE-2026-40899

CVSS 8.3v4.0pub. 2026-04-16upd. 2026-04-20

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto-generates a public setter for the illegalParameters field that contains the JDBC security blocklist. When a datasource configuration is submitted as JSON, Jackson deserialization calls setIllegalParameters with an attacker-supplied empty list, replacing the blocklist before getJdbc() validation runs. This allows an authenticated attacker to include dangerous JDBC parameters such as allowLoadLocalInfile=true, and by pointing the datasource at a rogue MySQL server, exploit the LOAD DATA LOCAL INFILE protocol feature to read arbitrary files from the DataEase server filesystem, including sensitive environment variables and database credentials. This issue has been fixed in version 2.10.21.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dataease

    APP
    Dataease
    < 2.10.21
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2026-32137CRITICAL9.3PL ✓same product

SQL Injection w Dataease — niekontrolowany parametr tabeli w podglądzie danych

CVE-2026-32140CRITICAL9.3PL ✓same product

Dataease: RCE poprzez path traversal w parametrze IniFile sterownika JDBC

CVE-2024-57707CRITICAL9.8PL ✓same product

RCE w DataEase v1 poprzez komponenty konta użytkownika i hasła

CVE-2024-56511CRITICAL9.3PL ✓same product

DataEase – obejście uwierzytelnienia przez path traversal w TokenFilter

CVE-2024-52295CRITICAL9.3PL ✓same product

DataEase: hardkodowany sekret JWT umożliwia przejęcie usługi