Description
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2428
https://github.com/dataease/dataease/releases/tag/v1.11.2
Related Vulnerabilities
CVE-2022-45688 Vulnerability in maven package cn.hutool:hutool-json
CVE-2023-49804 Vulnerability in npm package uptime-kuma
CVE-2023-34613 Vulnerability in maven package net.sf.sojo:sojo
CVE-2023-35931 Vulnerability in npm package shescape
CVE-2022-36883 Vulnerability in maven package org.jenkins-ci.plugins:git