Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In backend/src/main/java/io/dataease/provider/datasource/JdbcProvider.java, the MysqlConfiguration class does not filter any parameters. If an attacker adds some parameters to a JDBC url and connects to a malicious mysql server, the attacker can trigger the mysql jdbc deserialization vulnerability. Through the deserialization vulnerability, the attacker can execute system commands and obtain server privileges. Version 1.15.2 contains a patch for this issue.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39312.json",
"cwe_ids": [
"CWE-20",
"CWE-502"
]
}{
"cpe": "cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.15.2"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-22T02:08:01Z"
[
{
"target": {
"function": "getJdbc",
"file": "backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java"
},
"id": "CVE-2022-39312-0b8201f1",
"digest": {
"function_hash": "336527857516500295157118527924204461754",
"length": 621.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/dataease/dataease/commit/956ee2d6c9e81349a60aef435efc046888e10a6d"
},
{
"target": {
"file": "backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java"
},
"id": "CVE-2022-39312-c1bd2bd6",
"digest": {
"line_hashes": [
"92279100573955843084571770727989571696",
"91793398230803882612673307002192714427",
"68781991525331345110242083063685719500",
"39464785085311227024897654553810509231",
"240079964688278178017925997187609918774",
"264986517262341094214408618181422500601",
"203912701329597166123440158038131604713",
"77046907757357531708352768005274797509",
"196891557596699132768321838855448935884",
"48259344858155953583595535785484993587",
"276815561858916451502025018342150835970",
"101594560876218831957293608656646248670",
"148385709885320867279770780743750384799",
"269372095770589654208343042495615679270",
"326575412970396106722721842557057532291"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/dataease/dataease/commit/956ee2d6c9e81349a60aef435efc046888e10a6d"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39312.json"