DataEase是DataEase开源的一个开源的数据可视化分析工具。用于帮助用户快速分析数据并洞察业务趋势,从而实现业务的改进与优化。 DataEase 2.10.4之前版本存在安全漏洞,该漏洞源于存在鉴权漏洞,可以被绕过,造成未授权访问的风险。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | https://github.com/vulhub/vulhub/blob/master/dataease/CVE-2024-56511/README.md | POC详情 | |
| 2 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/DataEase%20%E7%99%BD%E5%90%8D%E5%8D%95%E8%B7%AF%E5%BE%84%E7%A9%BF%E8%B6%8A%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2024-56511.md | POC详情 |
| 3 | DataEase versions up to and including 2.10.3 contain an authentication bypass in `io.dataease.auth.filter.TokenFilter`. The filter passes the raw, unnormalized request URI to `WhitelistUtils.match()`, which only checks for whitelisted prefixes such as `/geo/`, `/customGeo/`, `/map/`, `/oauth2/`, and `/websocket` without resolving `..` segments. By prepending a whitelisted prefix and traversing back into the configured `server.servlet.context-path`, an attacker bypasses the filter while Tomcat still routes the request to the genuine, protected controller. This collapses the entire `/de2api` surface (user management, datasources, dashboards, exports) into unauthenticated access. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-56511.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论