{"id":"CVE-2024-23328","summary":"The Dataease datasource exists deserialization and arbitrary file read vulnerability","details":"Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.","aliases":["GHSA-8x8q-p622-jf25"],"modified":"2026-08-12T15:17:00.113720Z","published":"2024-02-01T15:40:24.236Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23328.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23328.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-8x8q-p622-jf25"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23328"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/4128adf5fc4592b55fa1722a53b178967545d46a"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/bb540e6dc83df106ac3253f331066129a7487d1a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"2034e5a42e939976dcfa1f747068dafb30a05ded"},{"introduced":"4061cb39c4cf46255e786aa8c1a071c6e8c8df48"},{"fixed":"7f1e1554e26fefc6757dcafdae1b9454c5aa1613"},{"fixed":"4128adf5fc4592b55fa1722a53b178967545d46a"},{"fixed":"bb540e6dc83df106ac3253f331066129a7487d1a"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.18.15"},{"introduced":"2.0.0"},{"fixed":"2.3.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*"}}],"versions":["v1.18.14","v2.2.0","v1.18.13","v1.18.12","v1.18.11","v1.18.10","v1.18.9","v1.18.8","v1.18.7","v1.18.6","v1.18.5","v1.18.4","v1.18.2","v1.18.1","v1.18.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23328.json","vanir_signatures_modified":"2026-08-12T15:17:00Z","vanir_signatures":[{"digest":{"line_hashes":["101298929573642802071728888223570198032","211158115149331556494079950685910576042","20409387090052583888599888847732403555","313580136280437354180077911461560633584","203689669310874037571948790632992157248","260709613932452681524294821432833176763","162231660585021236347394515046171883888"],"threshold":0.9},"id":"CVE-2024-23328-0de9f41e","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/4128adf5fc4592b55fa1722a53b178967545d46a","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"97944260125754802209164148591873657257","length":823},"id":"CVE-2024-23328-7dd337f4","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/bb540e6dc83df106ac3253f331066129a7487d1a","target":{"function":"getJdbc","file":"core/backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/4128adf5fc4592b55fa1722a53b178967545d46a","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java","function":"getJdbc"},"deprecated":false,"digest":{"function_hash":"224124216860304043126356016849640123402","length":832},"id":"CVE-2024-23328-f2cdc394"},{"deprecated":false,"digest":{"line_hashes":["227921309810093886447745292602092123603","207503627036353614434399969324411795082","102205775488946310278880868254245669999","99807020435073692125731227355217655226","8177927296778060150995971431014735495","122767931723005913550878415441619468711","141514417954721678671930180008596791698"],"threshold":0.9},"id":"CVE-2024-23328-f9826804","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/bb540e6dc83df106ac3253f331066129a7487d1a","target":{"file":"core/backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}