menu
techminis

A naukri.com initiative

google-web-stories
source image

Dev

1M

read

336

img
dot

Image Credit: Dev

Critical RCE Vulnerabilities Found in DataEase (CVE-2025-49001/49002)

  • Critical Remote Code Execution (RCE) vulnerabilities (CVE-2025-49001/49002) have been discovered in DataEase, an open-source data visualization platform.
  • The vulnerabilities allow unauthenticated RCE and authentication bypass, posing a significant risk to internet-facing deployments.
  • CVE-2025-48999 enables attackers to inject malicious JDBC parameters, CVE-2025-49002 allows code execution through JDBC parameters, and CVE-2025-49001 permits unauthorized access via JWT tokens.
  • Recommended mitigations include using WAF/Firewall, restricting outbound access, and upgrading to DataEase v2.10.10 to fix the vulnerabilities.

Read Full Article

like

20 Likes

For uninterrupted reading, download the app