{"id":"CVE-2025-62419","summary":"DataEase vulnerable to JDBC URL injection in DB2 and MongoDB data source configuration","details":"DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data source configuration handlers. In the DB2 data source handler, when the extraParams field is empty, the HOSTNAME, PORT, and DATABASE values are directly concatenated into the JDBC URL without filtering illegal parameters. This allows an attacker to inject a malicious JDBC string into the HOSTNAME field to bypass previously patched vulnerabilities CVE-2025-57773 and CVE-2025-58045. The vulnerability is fixed in version 2.10.14. No known workarounds exist.","aliases":["GHSA-x4x9-mjcf-99r9"],"modified":"2026-08-12T15:14:24.261997Z","published":"2025-10-17T17:11:21.730Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62419.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62419.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-x4x9-mjcf-99r9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62419"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"a4ead6790d5b492b0c3df87015d06ed4f6e5f6bb"},{"fixed":"bb320e42bf2cf862b9c4b438c1517547b53ed67b"}],"database_specific":{"cpe":"cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.10.14"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.10.13","v2.10.12","v2.10.11","v2.10.10","v2.10.9","v2.10.8","v2.10.7","v2.10.6","v2.10.5","v2.10.4","v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.6.0","v2.3.0","v2.2.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62419.json","vanir_signatures_modified":"2026-08-12T15:14:24Z","vanir_signatures":[{"target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java","function":"getJdbc"},"deprecated":false,"digest":{"length":1641,"function_hash":"318084826704619790610772079774174186110"},"id":"CVE-2025-62419-0af499a4","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b"},{"digest":{"line_hashes":["300202327132595654542184143276892963614","64814826359956964982846661677092555461","200740930809767147849093808931696596155","264288492134497320739890453482424408032","99314919101676472009868241285216565095"],"threshold":0.9},"id":"CVE-2025-62419-31e54d58","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"},"deprecated":false},{"source":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["67362837996066895491036262167965060049","203174799191427566620597313802144224224","156049878968505701786302864870376015886","234752437833024204454346191164166948173","22431626205809116371677207218277129167","90660312294940396502466310839285690339","338402733260982807093513345359714048446","130191747495566765357858499324510657492","206295369207005756868582631711476347642","304882748330065831637120837045279611863","272682536000375407452755664520058561300","278906348350596100948256357488316798402","315779692837072296632638343547471377864","198710618279807928606657002811482695105","93113150856017422359902813424132491185","5844953474518068538900810024937181993","146106484857196093929508950861568905169","120702208633995191995506407504246923727","224900650179496956064154970948632629370","255772802642667320584955123374174539061","191412058373830779299184249337151491217","253981056380976569661097632809119004774","134387664604078160170798364850475734274","280547399847225556066763418361261846428","67508245266982376806399218296004350249","72165126525473171270712977498410243268","267925214973108380156070610123931479246","221128677140524340466227054187331878455","277577523574876695115499673138300964459"]},"id":"CVE-2025-62419-361b8292","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/H2.java","function":"getJdbc"},"deprecated":false,"digest":{"length":394,"function_hash":"165582026122521307171476078308088389535"},"id":"CVE-2025-62419-6aae3f0b","signature_type":"Function","signature_version":"v1"},{"target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Sqlserver.java","function":"getJdbc"},"deprecated":false,"digest":{"function_hash":"318960114364821797717944728351483030031","length":894},"id":"CVE-2025-62419-7ed1009c","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b"},{"deprecated":false,"digest":{"function_hash":"29872308043758068843898774857508284295","length":1033},"id":"CVE-2025-62419-bc102fab","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Mongo.java","function":"getJdbc"}},{"deprecated":false,"digest":{"line_hashes":["272790013953672796150386807231842354032","316790544829683262421920958366598592612","45437300578907785385609087111929239441","143023399493550275290993194879647302229","185112485707262239357671148479975611999","67362837996066895491036262167965060049","203174799191427566620597313802144224224","313798964067752462055496936665699167670","72611738212555096123302341279181859506","12307248349436313364655556377503937698","22348761404364233469008510678833440339","130191747495566765357858499324510657492","143092853888342913541609941656534084694","61534903022848289666143264222584654882","339399043429898470319740350268593216005","293303267934028831687237817152907382769","257380347097024647005145612097371733395","295851067174469376536328938159221475801","310016689592048621447475453672826407255","230760160830348792250753675038327903560","23532363144827491563460843431178260591","255772802642667320584955123374174539061","197157854710776494115524897094803834866","119267620208540501041600515986837789320","67305898528663910404855856363929362337"],"threshold":0.9},"id":"CVE-2025-62419-c9bbed96","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Mongo.java"}},{"digest":{"line_hashes":["101298929573642802071728888223570198032","211158115149331556494079950685910576042","196967725599821495530650952443019033356","67362837996066895491036262167965060049","203174799191427566620597313802144224224","30967747474530908757100815227618851823","215342580806425070735781077706845799307","278886838750533404700070728723710056068","42407612547815857116493910769402279986","130191747495566765357858499324510657492","321175954285739019259605375178409805929","276479045699888881893501605582955016015","104579409215537307993293700482264147225","44767094788168607181159034949775712421","255772802642667320584955123374174539061","197157854710776494115524897094803834866","119267620208540501041600515986837789320","306732317927706533981229804896599266348","138624361646778758424324680305323299226"],"threshold":0.9},"id":"CVE-2025-62419-f09e02d1","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Sqlserver.java"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}