CVE-2025-32966

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-23 16:15

Updated : 2025-06-24 16:36


NVD link : CVE-2025-32966

Mitre link : CVE-2025-32966

CVE.ORG link : CVE-2025-32966


JSON object : View

Products Affected

dataease

  • dataease
CWE
CWE-290

Authentication Bypass by Spoofing