{"id":"CVE-2022-39312","summary":"Dataease Mysql Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerability","details":"Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In `backend/src/main/java/io/dataease/provider/datasource/JdbcProvider.java`, the `MysqlConfiguration` class does not filter any parameters. If an attacker adds some parameters to a JDBC url and connects to a malicious mysql server, the attacker can trigger the mysql jdbc deserialization vulnerability. Through the deserialization vulnerability, the attacker can execute system commands and obtain server privileges. Version 1.15.2 contains a patch for this issue.","aliases":["GHSA-q4qq-jhjv-7rh2"],"modified":"2026-08-12T13:33:12.654648Z","published":"2022-10-25T00:00:00Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20","CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39312.json"},"references":[{"type":"WEB","url":"https://github.com/dataease/dataease/releases/tag/v1.15.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39312.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-q4qq-jhjv-7rh2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39312"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/956ee2d6c9e81349a60aef435efc046888e10a6d"},{"type":"FIX","url":"https://github.com/dataease/dataease/pull/3328"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"6c3a011955c5c753ffd616d030bea5db4793c51c"},{"fixed":"956ee2d6c9e81349a60aef435efc046888e10a6d"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.15.2"}]}}],"versions":["v1.15.1","v1.15.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39312.json","vanir_signatures_modified":"2026-08-12T13:33:12Z","vanir_signatures":[{"source":"https://github.com/dataease/dataease/commit/956ee2d6c9e81349a60aef435efc046888e10a6d","target":{"file":"backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java","function":"getJdbc"},"deprecated":false,"digest":{"function_hash":"336527857516500295157118527924204461754","length":621},"id":"CVE-2022-39312-0b8201f1","signature_type":"Function","signature_version":"v1"},{"target":{"file":"backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java"},"deprecated":false,"digest":{"line_hashes":["92279100573955843084571770727989571696","91793398230803882612673307002192714427","68781991525331345110242083063685719500","39464785085311227024897654553810509231","240079964688278178017925997187609918774","264986517262341094214408618181422500601","203912701329597166123440158038131604713","77046907757357531708352768005274797509","196891557596699132768321838855448935884","48259344858155953583595535785484993587","276815561858916451502025018342150835970","101594560876218831957293608656646248670","148385709885320867279770780743750384799","269372095770589654208343042495615679270","326575412970396106722721842557057532291"],"threshold":0.9},"id":"CVE-2022-39312-c1bd2bd6","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/956ee2d6c9e81349a60aef435efc046888e10a6d"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}