DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which may cause the risk of unauthorized access. The vulnerability has been fixed in v2.10.6. No known workarounds are available.
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Vulnerability Complexity | None |
Vulnerability Impact | High |
Exploit Code Maturity | Proof-of-Concept |
Epss Score | 0.00043 |
---|---|
Epss Percentile | 0.11995 |
ریسک پائین:: این آسیب پذیری احتمال ارائه Exploit پائینی دارد. به روز رسانی و نظارت معمولی را لحاظ نمائید.