Description
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Remediation
References
https://github.com/dataease/dataease/issues/2428
https://github.com/dataease/dataease/releases/tag/v1.11.2
Related Vulnerabilities
CVE-2022-37223 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2023-1454 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-common
CVE-2021-3757 Vulnerability in npm package immer
CVE-2022-2047 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2021-41084 Vulnerability in maven package org.http4s:http4s-server_3