Description
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
Remediation
References
https://github.com/dataease/dataease/issues/2429
Related Vulnerabilities
CVE-2020-28442 Vulnerability in maven package org.webjars.npm:js-data
CVE-2021-23433 Vulnerability in npm package algoliasearch-helper
CVE-2020-36048 Vulnerability in maven package org.webjars.npm:engine.io
CVE-2021-21353 Vulnerability in npm package pug
CVE-2020-10968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind