{"id":"CVE-2024-55953","summary":"Dataease Mysql JDBC Connection Parameters Not Verified Leads to Deserialization and Arbitrary File Read Vulnerability","details":"DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through the background JDBC connection. When constructing the jdbc connection string, the parameters are not filtered. This vulnerability has been fixed in v1.18.27. Users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["GHSA-mrf3-9q84-rcmf"],"modified":"2026-08-12T14:52:20.784979Z","published":"2024-12-18T18:49:21.632Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55953.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55953.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-mrf3-9q84-rcmf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55953"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"8ef98d23903f02ceb8acb47a7d7b0d94f101841a"},{"fixed":"0db4872a52eccf6e83dd9359aa05db52dd580ec1"}],"database_specific":{"cpe":"cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.18.27"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.18.26","v1.18.25","v1.18.24","v1.18.23","v1.18.22","v1.18.21","v1.18.20","v1.18.19","v1.18.18","v1.18.17","v1.18.16","v1.18.15","v1.18.14","v1.18.13","v1.18.12","v1.18.11","v1.18.10","v1.18.9","v1.18.8","v1.18.7","v1.18.6","v1.18.5","v1.18.4","v1.18.2","v1.18.1","v1.18.0","v1.0.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["182020811269873562107125190754910561249","211813033230790611424771587951912403581","57337582411762295881712096135840195446","280007923929317372875221687807498300374","128510257947228004914677151373531963246","293523817602657175868052534546008082620","288941054251953737719927889299771581619","72300016693376521599945400195424610825","93825172376401972904535550460750309953","212905539354010951941153556065360704586","339081076206286176550930361940862426377","251558540287303364084949129756101299743","252537005507308565970068158990282149328","220835986688838450969177573477686574146","60993190871904727282994533602264452834","120818857908881743294034245613238993052","250027737239600429417243011452452358822","184025494455006886331475658494697605651","47434397264718337053212763965370049792"],"threshold":0.9},"id":"CVE-2024-55953-0a5e3094","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1","target":{"file":"core/backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java"}},{"deprecated":false,"digest":{"function_hash":"59479437966243511602363196126708312501","length":1293},"id":"CVE-2024-55953-163b86d0","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1","target":{"file":"core/backend/src/main/java/io/dataease/dto/datasource/PgConfiguration.java","function":"getJdbc"}},{"target":{"file":"core/backend/src/main/java/io/dataease/dto/datasource/RedshiftConfiguration.java"},"deprecated":false,"digest":{"line_hashes":["218604338777642790685069244835187176827","161697867944344940650229941559275140298","276024941085862390274501384254352179111","318734915464596835689845002971935087521","67691285599808025088434611024460295875","165961363543364429366420618669687425578","85272030021970046619457345544717630622","296480588419946036891787043011331740916","126696841720036977716321166245466609618","204060396382753599755753378797058614002","225136925195082835278059347613984463824"],"threshold":0.9},"id":"CVE-2024-55953-3c8b4489","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1","target":{"file":"core/backend/src/main/java/io/dataease/dto/datasource/RedshiftConfiguration.java","function":"getJdbc"},"deprecated":false,"digest":{"function_hash":"90181800386751477694627167903914398583","length":251},"id":"CVE-2024-55953-bd9ba31f"},{"deprecated":false,"digest":{"line_hashes":["170221171599612478595555909859717902215","182864902456935272141778159807704709696","57544332438300312335420175735713977294","244510898196010311882692744362070104571","159391496123703408365742860286397231131","66447004305530740707621100467205646864","290201130187511836121364603602625471643","101594560876218831957293608656646248670","188822854823644136722482190287678039421","279154043734763208390376870083329487572","177100154474042613142791097389531994528","319286234787647773437056350333996360132","79433877829888885633027275248318966662","198975878862715429353118892792686026085","93113150856017422359902813424132491185","298360722709620258700277702899131188927","42994657539220917030344839206183456629","25398738911736206921110734124899847034","303896877184790714387840253199643078422","93825172376401972904535550460750309953","293746793248191162618952762332632640130","133728314145255313478227056730619384680","264330893242590059124121951776668597730","222631649333180973453586663883566712989","311891237031764437091940699983999205709","238723273037389949721404006160678287539","119267620208540501041600515986837789320","67305898528663910404855856363929362337"],"threshold":0.9},"id":"CVE-2024-55953-eb83b2e8","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1","target":{"file":"core/backend/src/main/java/io/dataease/dto/datasource/PgConfiguration.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1","target":{"file":"core/backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java","function":"getJdbc"},"deprecated":false,"digest":{"function_hash":"218156284353965263201014183182410085122","length":912},"id":"CVE-2024-55953-f4e6fb56"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55953.json","vanir_signatures_modified":"2026-08-12T14:52:20Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}