DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has been patched in version 2.10.11.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-153"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53005.json"
}[
{
"target": {
"function": "getJdbc",
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
},
"signature_version": "v1",
"digest": {
"length": 241.0,
"function_hash": "183003779497483947224845251740197970733"
},
"source": "https://github.com/dataease/dataease/commit/872597925338dbf16f6af9e5b66ba4fbb6907514",
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-53005-44d1aec3"
},
{
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"100456944153765217509785831818021985500",
"42185638248660599097384144752533775061",
"262806380832579929368515941997875256289",
"283362053816985036004927096577222560716",
"334081505712768125582536326672569134219",
"159267869677055451445996061063063280061",
"333487707478739931352209523162417589534",
"228091582504442549553598166391130391852"
],
"threshold": 0.9
},
"source": "https://github.com/dataease/dataease/commit/872597925338dbf16f6af9e5b66ba4fbb6907514",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-53005-d3b14c21"
}
]