DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data source configuration handlers. In the DB2 data source handler, when the extraParams field is empty, the HOSTNAME, PORT, and DATABASE values are directly concatenated into the JDBC URL without filtering illegal parameters. This allows an attacker to inject a malicious JDBC string into the HOSTNAME field to bypass previously patched vulnerabilities CVE-2025-57773 and CVE-2025-58045. The vulnerability is fixed in version 2.10.14. No known workarounds exist.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-502"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62419.json"
}{
"cpe": "cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.14"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62419.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "318084826704619790610772079774174186110",
"length": 1641
},
"id": "CVE-2025-62419-0af499a4",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java",
"function": "getJdbc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"300202327132595654542184143276892963614",
"64814826359956964982846661677092555461",
"200740930809767147849093808931696596155",
"264288492134497320739890453482424408032",
"99314919101676472009868241285216565095"
],
"threshold": 0.9
},
"id": "CVE-2025-62419-31e54d58",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"67362837996066895491036262167965060049",
"203174799191427566620597313802144224224",
"156049878968505701786302864870376015886",
"234752437833024204454346191164166948173",
"22431626205809116371677207218277129167",
"90660312294940396502466310839285690339",
"338402733260982807093513345359714048446",
"130191747495566765357858499324510657492",
"206295369207005756868582631711476347642",
"304882748330065831637120837045279611863",
"272682536000375407452755664520058561300",
"278906348350596100948256357488316798402",
"315779692837072296632638343547471377864",
"198710618279807928606657002811482695105",
"93113150856017422359902813424132491185",
"5844953474518068538900810024937181993",
"146106484857196093929508950861568905169",
"120702208633995191995506407504246923727",
"224900650179496956064154970948632629370",
"255772802642667320584955123374174539061",
"191412058373830779299184249337151491217",
"253981056380976569661097632809119004774",
"134387664604078160170798364850475734274",
"280547399847225556066763418361261846428",
"67508245266982376806399218296004350249",
"72165126525473171270712977498410243268",
"267925214973108380156070610123931479246",
"221128677140524340466227054187331878455",
"277577523574876695115499673138300964459"
],
"threshold": 0.9
},
"id": "CVE-2025-62419-361b8292",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "165582026122521307171476078308088389535",
"length": 394
},
"id": "CVE-2025-62419-6aae3f0b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java",
"function": "getJdbc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "318960114364821797717944728351483030031",
"length": 894
},
"id": "CVE-2025-62419-7ed1009c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Sqlserver.java",
"function": "getJdbc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "29872308043758068843898774857508284295",
"length": 1033
},
"id": "CVE-2025-62419-bc102fab",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Mongo.java",
"function": "getJdbc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"272790013953672796150386807231842354032",
"316790544829683262421920958366598592612",
"45437300578907785385609087111929239441",
"143023399493550275290993194879647302229",
"185112485707262239357671148479975611999",
"67362837996066895491036262167965060049",
"203174799191427566620597313802144224224",
"313798964067752462055496936665699167670",
"72611738212555096123302341279181859506",
"12307248349436313364655556377503937698",
"22348761404364233469008510678833440339",
"130191747495566765357858499324510657492",
"143092853888342913541609941656534084694",
"61534903022848289666143264222584654882",
"339399043429898470319740350268593216005",
"293303267934028831687237817152907382769",
"257380347097024647005145612097371733395",
"295851067174469376536328938159221475801",
"310016689592048621447475453672826407255",
"230760160830348792250753675038327903560",
"23532363144827491563460843431178260591",
"255772802642667320584955123374174539061",
"197157854710776494115524897094803834866",
"119267620208540501041600515986837789320",
"67305898528663910404855856363929362337"
],
"threshold": 0.9
},
"id": "CVE-2025-62419-c9bbed96",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Mongo.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"101298929573642802071728888223570198032",
"211158115149331556494079950685910576042",
"196967725599821495530650952443019033356",
"67362837996066895491036262167965060049",
"203174799191427566620597313802144224224",
"30967747474530908757100815227618851823",
"215342580806425070735781077706845799307",
"278886838750533404700070728723710056068",
"42407612547815857116493910769402279986",
"130191747495566765357858499324510657492",
"321175954285739019259605375178409805929",
"276479045699888881893501605582955016015",
"104579409215537307993293700482264147225",
"44767094788168607181159034949775712421",
"255772802642667320584955123374174539061",
"197157854710776494115524897094803834866",
"119267620208540501041600515986837789320",
"306732317927706533981229804896599266348",
"138624361646778758424324680305323299226"
],
"threshold": 0.9
},
"id": "CVE-2025-62419-f09e02d1",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Sqlserver.java"
}
}
]
"2026-08-12T15:14:24Z"