目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-56511— DataEase 安全漏洞

一分钟漏洞结论

影响对象
dataease dataease
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

DataEase是DataEase开源的一个开源的数据可视化分析工具。用于帮助用户快速分析数据并洞察业务趋势,从而实现业务的改进与优化。 DataEase 2.10.4之前版本存在安全漏洞,该漏洞源于存在鉴权漏洞,可以被绕过,造成未授权访问的风险。

AI 预测 9.1 利用难度: 较易 EPSS 44.46% · P99

公开利用映射 1

获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-56511 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
DataEase has an unauthorized vulnerability
来源: CVE Program / CVE List V5
Vulnerability Description
DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause the risk of unauthorized access. In the io.dataease.auth.filter.TokenFilter class, ”request.getRequestURI“ is used to obtain the request URL, and it is passed to the "WhitelistUtils.match" method to determine whether the URL request is an interface that does not require authentication. The "match" method filters semicolons, but this is not enough. When users set "server.servlet.context-path" when deploying products, there is still a risk of being bypassed, which can be bypassed by any whitelist prefix /geo/../context-path/. The vulnerability has been fixed in v2.10.4.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
使用候选名称进行的认证绕过
来源: CVE Program / CVE List V5
Vulnerability Title
DataEase 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
DataEase是DataEase开源的一个开源的数据可视化分析工具。用于帮助用户快速分析数据并洞察业务趋势,从而实现业务的改进与优化。 DataEase 2.10.4之前版本存在安全漏洞,该漏洞源于存在鉴权漏洞,可以被绕过,造成未授权访问的风险。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
dataease dataease < 2.10.4 -

二、漏洞 CVE-2024-56511 的公开POC

# POC 描述 源链接 神龙链接
1 https://github.com/vulhub/vulhub/blob/master/dataease/CVE-2024-56511/README.md POC详情
2 None https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/DataEase%20%E7%99%BD%E5%90%8D%E5%8D%95%E8%B7%AF%E5%BE%84%E7%A9%BF%E8%B6%8A%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2024-56511.md POC详情
3 DataEase versions up to and including 2.10.3 contain an authentication bypass in `io.dataease.auth.filter.TokenFilter`. The filter passes the raw, unnormalized request URI to `WhitelistUtils.match()`, which only checks for whitelisted prefixes such as `/geo/`, `/customGeo/`, `/map/`, `/oauth2/`, and `/websocket` without resolving `..` segments. By prepending a whitelisted prefix and traversing back into the configured `server.servlet.context-path`, an attacker bypasses the filter while Tomcat still routes the request to the genuine, protected controller. This collapses the entire `/de2api` surface (user management, datasources, dashboards, exports) into unauthenticated access. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-56511.yaml POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-56511 的情报信息

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-56511

暂无评论


发表评论