Metrics
Affected Vendors & Products
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 13 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dataease
Dataease dataease |
|
CPEs | cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dataease
Dataease dataease |
|
Metrics |
cvssV3_1
|
Wed, 13 Nov 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has been fixed in v2.10.2. | |
Title | DataEase has a forged JWT token vulnerability | |
Weaknesses | CWE-798 | |
References |
| |
Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-13T15:49:20.363Z
Updated: 2024-11-21T15:03:25.532Z
Reserved: 2024-11-06T19:00:26.394Z
Link: CVE-2024-52295
Updated: 2024-11-13T18:57:28.360Z
Status : Awaiting Analysis
Published: 2024-11-13T16:15:19.550
Modified: 2024-11-21T15:15:32.900
Link: CVE-2024-52295
No data.