Description
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2428
https://github.com/dataease/dataease/releases/tag/v1.11.2
Related Vulnerabilities
CVE-2017-15878 Vulnerability in npm package keystone
CVE-2020-8116 Vulnerability in maven package org.webjars.npm:dot-prop
CVE-2021-23337 Vulnerability in maven package org.webjars:lodash
CVE-2022-37258 Vulnerability in npm package steal
CVE-2023-30514 Vulnerability in maven package org.jenkins-ci.plugins:azure-keyvault