← back
CVE-2025-49001highCWE-287

Dataease Authentication Bypass Vulnerability

41Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.7epss 21%
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
dataease · dataease