{"id":"CVE-2026-45534","summary":"DataEase: RCE Vulnerability","details":"DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty(\"java.io.tmpdir\"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so com.amazon.redshift.Driver#connect, com.amazon.redshift.Driver#getJdbcIniFile, and com.amazon.redshift.util.ObjectFactory#instantiate execute a reflection-based remote code execution chain during a normal JDBC connection through io.dataease.datasource.type.Redshift. This issue is fixed in version 2.10.23.","aliases":["GHSA-cv4c-8rpv-2x97"],"modified":"2026-07-22T04:18:29.573071Z","published":"2026-07-15T19:19:10.873Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45534.json"},"references":[{"type":"WEB","url":"https://github.com/dataease/dataease/releases/tag/v2.10.23"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45534.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-cv4c-8rpv-2x97"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45534"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/3e58149f1e014b1a7ae2c12134b37ae438f676ac"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"3e58149f1e014b1a7ae2c12134b37ae438f676ac"},{"fixed":"cd4844cc45049e73a53d65e3a58454a167a3dffb"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.10.23"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.10.22","v2.10.21","v2.10.20","v2.10.19","v2.10.18","v2.10.17","v2.10.16","v2.10.15","v2.10.14","v2.10.13","v2.10.12","v2.10.11","v2.10.10","v2.10.9","v2.10.8","v2.10.7","v2.10.6","v2.10.5","v2.10.4","v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.6.0","v2.3.0","v2.2.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45534.json","vanir_signatures_modified":"2026-07-22T04:18:29Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/3e58149f1e014b1a7ae2c12134b37ae438f676ac","target":{"file":"core/core-backend/src/main/java/io/dataease/CoreApplication.java"},"deprecated":false,"digest":{"line_hashes":["15821317397347673482983527820989049626","34777742503710241182623721919297647880","17358568406595948050264051915989166974","218444518956152575236350449743578772568"],"threshold":0.9},"id":"CVE-2026-45534-0a848064"},{"signature_version":"v1","source":"https://github.com/dataease/dataease/commit/3e58149f1e014b1a7ae2c12134b37ae438f676ac","target":{"file":"core/core-backend/src/main/java/io/dataease/CoreApplication.java","function":"main"},"deprecated":false,"digest":{"function_hash":"113493415089312803196753409193036914026","length":141},"id":"CVE-2026-45534-19abf907","signature_type":"Function"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}