Description
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2428
https://github.com/dataease/dataease/releases/tag/v1.11.2
Related Vulnerabilities
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:github-com-faisalman-ua-parser-js
CVE-2022-0436 Vulnerability in maven package org.webjars.npm:grunt
CVE-2021-23346 Vulnerability in maven package org.webjars.npm:html-parse-stringify2
CVE-2014-3603 Vulnerability in maven package org.opensaml:opensaml
CVE-2023-45136 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates