Executive brief
DataEase, an open-source data visualization and analysis tool, contains a security flaw that allows any logged-in user to access the system's internal database. By sending a specially crafted request, an attacker can bypass security checks to run arbitrary database commands. This could lead to the theft of sensitive information, including user credentials, phone numbers, and private encryption keys, potentially allowing a full takeover of the system.
Technical details
A missing authorization vulnerability (CWE-862) exists in the '/de2api/datasetData/previewSql' endpoint of DataEase due to the absence of the '@DePermit' permission validation annotation. An authenticated attacker can exploit this by providing a 'datasourceId' of -1 in a POST request, which directs the query to the system's built-in engine database rather than a user-defined source. This allows for the execution of arbitrary SQL statements, enabling the retrieval of sensitive core data such as user credentials, RSA private keys, and administrator information. The issue is resolved in version 2.10.24 by adding the necessary permission annotations to the 'DatasetDataApi' interface.
Affected products
- DataEase DataEase < 2.10.24
Timeline
- 2026-06-18: advisory: GitHub Security Advisory published
- 2026-07-07: disclosed: CVE published to NVD
- 2026-07-07: patched: Fix committed to repository