{"id":"CVE-2026-45417","summary":"DataEase: SQL injection vulnerability","details":"DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into getTablesSql and execute the resulting SQL with executeQuery in io.dataease.datasource.provider.CalciteProvider#checkStatus, allowing SQL injection against DB2, SQL Server, PostgreSQL, and other affected datasources. This issue is fixed in version 2.10.23.","aliases":["GHSA-rg6c-r9mv-39fr"],"modified":"2026-08-12T16:24:37.653852Z","published":"2026-07-15T19:20:16.815Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45417.json"},"references":[{"type":"WEB","url":"https://github.com/dataease/dataease/releases/tag/v2.10.23"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45417.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-rg6c-r9mv-39fr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45417"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/f1c7204da1787ef812ee23cd3d51a1824126c1fb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"f1c7204da1787ef812ee23cd3d51a1824126c1fb"},{"fixed":"cd4844cc45049e73a53d65e3a58454a167a3dffb"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.10.23"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.10.22","v2.10.21","v2.10.20","v2.10.19","v2.10.18","v2.10.17","v2.10.16","v2.10.15","v2.10.14","v2.10.13","v2.10.12","v2.10.11","v2.10.10","v2.10.9","v2.10.8","v2.10.7","v2.10.6","v2.10.5","v2.10.4","v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.6.0","v2.3.0","v2.2.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45417.json","vanir_signatures_modified":"2026-08-12T16:24:37Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["251966269030471158210763038773937703713","152140526888442424927093821224371168640","98317190100959821919257272247817462358","109449290828259464407291295065986919908","300835148426046848144351715091563506516","111777145007894622803555318160985325042","277326886418457055886512401077902810502","38265887824406160378319277560054859396","191482072547947110682085703516860812079","125676910877747888141173466977370686736","26976863509166663722449391996084371810","281479817434462529213137902248325504508","293183741262895615822647066060099705275","197740907360684462032031292033944229328","129882879415906421770522452116620167019","63667118815215785404511106106092444195","257230282799577256492790103560635176709","333697419602753435997800398171492187934","325335343886475544267181806736541551677","308088080719316804935164816717065670772","336073639966378915874141035576099244534","73347941828970477712856099429742206564","291606042815377217878902385690937476735","176423015931070985060832878428999207381","285759592107226381130291091855699709746","335935316941560674237276934709574373158","39478336676801229052677389785097704035","20896511773268668416970741316948181002","107323810886491779616707682861870107735","92721858560817951569043838250128314917","273040903226650296599948163153320805018","306330450281227985809805709699092308394","189703134168958433678711455789682549222","90918371612547072305277591444921500488","330384769322420093383190776589836469940","230511961118522400417043447264814048283","279146837291953145451970939716745791786","89388955619886558528748688998434157261","140823449322537285989209707806610959718","210739732173159872273844557507012505253","286116339961227098132901993478840244979","253648135633619756761785301990107631","331853073170624173117088475149126538971","90393237063694253018919869775929825135","222818944095654770947047675558910544591","218954156151131470710064070183686761437","130286752474559114696320214877121898749","36313234784753864378195253418338270227","304161651868930821179231620480411759108","317669863644934680050711010416637950951","185114343798474677814106808446667748061","253023394682376770599386094346924543492","267886151198379081039265459288745859792","167139815257582784777467368815825641575","111222528728228954870589326212464747876","24956525641156394216205966829943486073","68575251857228975877334962949285982376","68394676975542844407170377614788067698","317312071402904226958941474942913988337","2633089752837378129644044728274698745","93165302863925124915799143243188697610","62164203623956015709921725174466828121","278609336583588170018042671179241161487","36110713665307827596165682055096456049","334155366914976618882878011513868000702","160532552708089307721302110611574908296","302908413068654530567022917100000547872","270347977455092791785610167450524340007","180939794595990146470208567324593855714","234685307103567000567255622417485249492","108867133935041253769108482717112075283","231467304903104144418929956780342651058","240266746917912427521744913791524541609","162869415115698753519440623875891223435","286492822212946339687749069254299162922","106200718134500337070655136385804331712","279669542207965495462452182314215141758","128231233066879320251526197474116838115","260858829686830027037842341371058346257","231133338997592913186138623157344916536","228369068981923437830739485737496819238","194460419279137619882200328832258776808","219672463562352868005935688107503129900","328551588311341908756665653410046961052","23190219415698365118560263160607484964","57581425146403835250020669410899451074","312861693351905434404272395914128768514","284477782437256963325588909867783254687","329555820916389888575667446531632748244","145900420395426390996414223134950292921"],"threshold":0.9},"id":"CVE-2026-45417-3975373a","signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/f1c7204da1787ef812ee23cd3d51a1824126c1fb","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/provider/CalciteProvider.java"}},{"digest":{"length":851,"function_hash":"329386586615389218299105623830596211997"},"id":"CVE-2026-45417-5dbf5c97","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/f1c7204da1787ef812ee23cd3d51a1824126c1fb","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/provider/CalciteProvider.java","function":"checkStatus"},"deprecated":false},{"id":"CVE-2026-45417-5dd6f9b9","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/f1c7204da1787ef812ee23cd3d51a1824126c1fb","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/provider/CalciteProvider.java","function":"getTablesSql"},"deprecated":false,"digest":{"function_hash":"118709125812431184726953446544593690659","length":7053}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/f1c7204da1787ef812ee23cd3d51a1824126c1fb","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/provider/CalciteProvider.java","function":"getTables"},"deprecated":false,"digest":{"function_hash":"265711665951740703764736781603086937552","length":577},"id":"CVE-2026-45417-9398bfc3"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}