Description
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
Remediation
References
https://github.com/dataease/dataease/issues/2429
Related Vulnerabilities
CVE-2019-10791 Vulnerability in npm package promise-probe
CVE-2022-38900 Vulnerability in maven package org.webjars.npm:decode-uri-component
CVE-2020-35491 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2018-3728 Vulnerability in npm package hoek
CVE-2022-45921 Vulnerability in maven package io.fusionauth:fusionauth-java-client