DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in Java in which the character "ı" becomes "I" when converted to uppercase, and the character "ſ" becomes "S" when converted to uppercase. A threat actor who uses a carefully crafted message that exploits this character conversion can cause remote code execution. The vulnerability has been fixed in v2.10.11. No known workarounds are available.
{
"cwe_ids": [
"CWE-153"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49003.json",
"cna_assigner": "GitHub_M"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49003.json"
"2026-04-12T16:41:28Z"
[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 241.0,
"function_hash": "183003779497483947224845251740197970733"
},
"source": "https://github.com/dataease/dataease/commit/872597925338dbf16f6af9e5b66ba4fbb6907514",
"id": "CVE-2025-49003-44d1aec3",
"signature_type": "Function",
"target": {
"function": "getJdbc",
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"100456944153765217509785831818021985500",
"42185638248660599097384144752533775061",
"262806380832579929368515941997875256289",
"283362053816985036004927096577222560716",
"334081505712768125582536326672569134219",
"159267869677055451445996061063063280061",
"333487707478739931352209523162417589534",
"228091582504442549553598166391130391852"
]
},
"source": "https://github.com/dataease/dataease/commit/872597925338dbf16f6af9e5b66ba4fbb6907514",
"id": "CVE-2025-49003-d3b14c21",
"signature_type": "Line",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
}
}
]