CVE-2025-49002
Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 50.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
- CVSS 4.0
- 8.2 HIGHCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 50.27% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- dataease/dataease
- Source
- security-advisories@github.com
References
- https://github.com/dataease/dataease/security/advisories/GHSA-999m-jv2p-5h34Exploit, Third Party Advisory
- https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7Exploit, Third Party Advisory
- https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.