PT-2026-60276 · Dataease · Dataease
CVE-2026-45534
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
DataEase versions prior to 2.10.23
Description
Redshift datasource connections can load a malicious
rsjdbc.ini configuration file from the directory specified by java.io.tmpdir. By setting the socketFactory variable to org.springframework.context.support.FileSystemXmlApplicationContext, a reflection-based remote code execution chain is triggered during a standard JDBC connection via io.dataease.datasource.type.Redshift. This process involves the execution of the connect(), getJdbcIniFile(), and instantiate() functions within the Redshift driver and utility classes.Recommendations
Update to version 2.10.23.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dataease