Description
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2428
https://github.com/dataease/dataease/releases/tag/v1.11.2
Related Vulnerabilities
CVE-2022-36885 Vulnerability in maven package com.coravy.hudson.plugins.github:github
CVE-2023-50481 Vulnerability in npm package blinksocks
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-api
CVE-2023-33544 Vulnerability in maven package io.hawt:hawtio-system
CVE-2021-43570 Vulnerability in maven package com.starkbank.ellipticcurve:starkbank-ecdsa