Description
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2428
https://github.com/dataease/dataease/releases/tag/v1.11.2
Related Vulnerabilities
CVE-2019-11002 Vulnerability in npm package materialize-css
CVE-2023-30519 Vulnerability in maven package org.jenkins-ci.plugins:quayio-trigger
CVE-2021-23518 Vulnerability in npm package cached-path-relative
CVE-2021-43571 Vulnerability in npm package starkbank-ecdsa
CVE-2023-0044 Vulnerability in maven package io.quarkus:quarkus-security-webauthn