logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-52295

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-52295

Description:
DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has been fixed in v2.10.2.
Last updated date:
02/20/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/20/2025
Reference url to background

https://github.com/dataease/dataease/security/advisories/GHSA-45v9-gfcv-xcq6

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy