← back
CVE-2025-49001highCWE-287

Dataease Authentication Bypass Vulnerability

41Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.7epss 22%
exploitation probability
22%top 3% of all CVEs
observed exploitation
nono source reports it
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
dataease · dataease