DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality. The difference lies in that "sslfactory" and related parameters need to be triggered after establishing the connection. Other similar parameters include "sslhostnameverifier", "sslpasswordcallback", and "authenticationPluginClassName". This issue has been patched in 2.10.11.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Jul 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality. The difference lies in that "sslfactory" and related parameters need to be triggered after establishing the connection. Other similar parameters include "sslhostnameverifier", "sslpasswordcallback", and "authenticationPluginClassName". This issue has been patched in 2.10.11. | |
Title | Dataease PostgreSQL & Redshift Data Source JDBC Connection Parameters Bypass Vulnerability | |
Weaknesses | CWE-153 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-02T14:22:31.107Z
Updated: 2025-07-02T14:37:30.510Z
Reserved: 2025-06-24T03:50:36.795Z
Link: CVE-2025-53006

Updated: 2025-07-02T14:36:39.482Z

Status : Awaiting Analysis
Published: 2025-07-02T15:15:27.343
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-53006

No data.