Skip to content

DataEase has database configuration information exposure vulnerability

Moderate
fit2cloudrd published GHSA-8gvx-4qvj-6vv5 Apr 7, 2024

Package

maven io.dataease (Maven)

Affected versions

<= 2.4.1

Patched versions

2.5.0

Description

Impact

DataEase has database configuration information exposure vulnerability。

Visiting the /de2api/engine/getEngine;.js path via a browser reveals that the platform's database configuration is returned.
image

Affected versions: <= 2.4.1

Patches

The vulnerability has been fixed in v2.5.0.

Workarounds

It is recommended to upgrade the version to v2.5.0.

References

If you have any questions or comments about this advisory:

Open an issue in https://github.com/dataease/dataease
Email us at wei@fit2cloud.com

Severity

Moderate

CVE ID

CVE-2024-30269

Weaknesses

No CWEs