CVE-2024-46985

HIGH

Dataease < 2.10.1 - XXE

Title source: rule
STIX 2.1

Description

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An attacker can construct a payload to implement intranet detection and file reading. The vulnerability has been fixed in v2.10.1.

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 51.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (2)
dataease/dataease < 2.10.1
io.dataease/common 0 - 2.10.1Maven
Published Sep 23, 2024
Tracked Since Feb 18, 2026