Description
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2428
https://github.com/dataease/dataease/releases/tag/v1.11.2
Related Vulnerabilities
CVE-2022-2466 Vulnerability in maven package io.quarkus:quarkus-smallrye-graphql
CVE-2020-14967 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2022-41940 Vulnerability in maven package org.webjars.npm:engine.io
CVE-2020-26256 Vulnerability in maven package org.webjars.npm:fast-csv
CVE-2023-34093 Vulnerability in npm package @strapi/database