Description
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2428
https://github.com/dataease/dataease/releases/tag/v1.11.2
Related Vulnerabilities
CVE-2022-25847 Vulnerability in npm package serve-lite
CVE-2019-12041 Vulnerability in maven package org.webjars.bower:remarkable
CVE-2020-16024 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-26136 Vulnerability in maven package org.webjars.bowergithub.salesforce:tough-cookie
CVE-2022-25883 Vulnerability in maven package org.webjars.npm:semver