CVE-2023-33963

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7. There are no known workarounds aside from upgrading.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

08 Jun 2023, 19:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-502
CPE cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
First Time Dataease
Dataease dataease
References (MISC) https://github.com/dataease/dataease/releases/tag/v1.18.7 - (MISC) https://github.com/dataease/dataease/releases/tag/v1.18.7 - Release Notes
References (MISC) https://github.com/dataease/dataease/security/advisories/GHSA-m26j-gh4m-xh9f - (MISC) https://github.com/dataease/dataease/security/advisories/GHSA-m26j-gh4m-xh9f - Exploit, Vendor Advisory

01 Jun 2023, 17:29

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-01 16:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-33963

Mitre link : CVE-2023-33963

CVE.ORG link : CVE-2023-33963


JSON object : View

Products Affected

dataease

  • dataease
CWE
CWE-502

Deserialization of Untrusted Data