{"id":"CVE-2025-48999","summary":"Dataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE Vulnerability","details":"DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if statement and will not be filtered. The payload can be directly concatenated at the replace location to construct a malicious JDBC statement. Version 2.10.10 contains a patch for the issue.","aliases":["GHSA-6pq2-6q8x-mp2r"],"modified":"2026-08-12T14:52:41.171005Z","published":"2025-06-03T20:31:13.950Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-284","CWE-923"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48999.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48999.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-6pq2-6q8x-mp2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48999"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/03b18db8a0fb7e9dc2c44f6d26d8c6221b7748c4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"3b8f018abb6d3846a7ebb694bbe5cbf35a932104"},{"fixed":"03b18db8a0fb7e9dc2c44f6d26d8c6221b7748c4"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.10.10"}]}}],"versions":["v2.10.9","v2.10.8","v2.10.7","v2.10.6","v2.10.5","v2.10.4","v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.6.0","v2.3.0","v2.2.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48999.json","vanir_signatures_modified":"2026-08-12T14:52:41Z","vanir_signatures":[{"id":"CVE-2025-48999-6f3f63f0","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/03b18db8a0fb7e9dc2c44f6d26d8c6221b7748c4","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Redshift.java","function":"getJdbc"},"deprecated":false,"digest":{"length":368,"function_hash":"108583883577562457624925327870902475567"}},{"digest":{"line_hashes":["27627074303964318882417323486351141630","97142947938543604819636395956544387028","40377677079330361915937831577686115372","121216136401205500103447404652187148247","21984936131719803008643477252148025788","197609987962733016545062199879861464352","317143147435927274322284371066829771593","176467234526973742004517108321347979027","123081837941841445117286324272641639305","230413827549299870676532268452966731911","155492726525485500818202825548485514582","15449972454824085861570954098415939735"],"threshold":0.9},"id":"CVE-2025-48999-dc201d4d","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/03b18db8a0fb7e9dc2c44f6d26d8c6221b7748c4","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Redshift.java"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}