CVE-2025-62419

Source
https://cve.org/CVERecord?id=CVE-2025-62419
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62419.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62419
Aliases
  • GHSA-x4x9-mjcf-99r9
Published
2025-10-17T17:11:21Z
Modified
2026-08-12T15:14:24Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
DataEase vulnerable to JDBC URL injection in DB2 and MongoDB data source configuration
Details

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data source configuration handlers. In the DB2 data source handler, when the extraParams field is empty, the HOSTNAME, PORT, and DATABASE values are directly concatenated into the JDBC URL without filtering illegal parameters. This allows an attacker to inject a malicious JDBC string into the HOSTNAME field to bypass previously patched vulnerabilities CVE-2025-57773 and CVE-2025-58045. The vulnerability is fixed in version 2.10.14. No known workarounds exist.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-502"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62419.json"
}
References

Affected packages

Git / github.com/dataease/dataease

Affected ranges

Type
GIT
Repo
https://github.com/dataease/dataease
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.10.14"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v2.*
v2.10.0
v2.10.1
v2.10.10
v2.10.11
v2.10.12
v2.10.13
v2.10.2
v2.10.3
v2.10.4
v2.10.5
v2.10.6
v2.10.7
v2.10.8
v2.10.9
v2.2.0
v2.3.0
v2.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62419.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "318084826704619790610772079774174186110",
            "length": 1641
        },
        "id": "CVE-2025-62419-0af499a4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java",
            "function": "getJdbc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "300202327132595654542184143276892963614",
                "64814826359956964982846661677092555461",
                "200740930809767147849093808931696596155",
                "264288492134497320739890453482424408032",
                "99314919101676472009868241285216565095"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-62419-31e54d58",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "67362837996066895491036262167965060049",
                "203174799191427566620597313802144224224",
                "156049878968505701786302864870376015886",
                "234752437833024204454346191164166948173",
                "22431626205809116371677207218277129167",
                "90660312294940396502466310839285690339",
                "338402733260982807093513345359714048446",
                "130191747495566765357858499324510657492",
                "206295369207005756868582631711476347642",
                "304882748330065831637120837045279611863",
                "272682536000375407452755664520058561300",
                "278906348350596100948256357488316798402",
                "315779692837072296632638343547471377864",
                "198710618279807928606657002811482695105",
                "93113150856017422359902813424132491185",
                "5844953474518068538900810024937181993",
                "146106484857196093929508950861568905169",
                "120702208633995191995506407504246923727",
                "224900650179496956064154970948632629370",
                "255772802642667320584955123374174539061",
                "191412058373830779299184249337151491217",
                "253981056380976569661097632809119004774",
                "134387664604078160170798364850475734274",
                "280547399847225556066763418361261846428",
                "67508245266982376806399218296004350249",
                "72165126525473171270712977498410243268",
                "267925214973108380156070610123931479246",
                "221128677140524340466227054187331878455",
                "277577523574876695115499673138300964459"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-62419-361b8292",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "165582026122521307171476078308088389535",
            "length": 394
        },
        "id": "CVE-2025-62419-6aae3f0b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java",
            "function": "getJdbc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "318960114364821797717944728351483030031",
            "length": 894
        },
        "id": "CVE-2025-62419-7ed1009c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Sqlserver.java",
            "function": "getJdbc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "29872308043758068843898774857508284295",
            "length": 1033
        },
        "id": "CVE-2025-62419-bc102fab",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Mongo.java",
            "function": "getJdbc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "272790013953672796150386807231842354032",
                "316790544829683262421920958366598592612",
                "45437300578907785385609087111929239441",
                "143023399493550275290993194879647302229",
                "185112485707262239357671148479975611999",
                "67362837996066895491036262167965060049",
                "203174799191427566620597313802144224224",
                "313798964067752462055496936665699167670",
                "72611738212555096123302341279181859506",
                "12307248349436313364655556377503937698",
                "22348761404364233469008510678833440339",
                "130191747495566765357858499324510657492",
                "143092853888342913541609941656534084694",
                "61534903022848289666143264222584654882",
                "339399043429898470319740350268593216005",
                "293303267934028831687237817152907382769",
                "257380347097024647005145612097371733395",
                "295851067174469376536328938159221475801",
                "310016689592048621447475453672826407255",
                "230760160830348792250753675038327903560",
                "23532363144827491563460843431178260591",
                "255772802642667320584955123374174539061",
                "197157854710776494115524897094803834866",
                "119267620208540501041600515986837789320",
                "67305898528663910404855856363929362337"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-62419-c9bbed96",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Mongo.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "101298929573642802071728888223570198032",
                "211158115149331556494079950685910576042",
                "196967725599821495530650952443019033356",
                "67362837996066895491036262167965060049",
                "203174799191427566620597313802144224224",
                "30967747474530908757100815227618851823",
                "215342580806425070735781077706845799307",
                "278886838750533404700070728723710056068",
                "42407612547815857116493910769402279986",
                "130191747495566765357858499324510657492",
                "321175954285739019259605375178409805929",
                "276479045699888881893501605582955016015",
                "104579409215537307993293700482264147225",
                "44767094788168607181159034949775712421",
                "255772802642667320584955123374174539061",
                "197157854710776494115524897094803834866",
                "119267620208540501041600515986837789320",
                "306732317927706533981229804896599266348",
                "138624361646778758424324680305323299226"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-62419-f09e02d1",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/bb320e42bf2cf862b9c4b438c1517547b53ed67b",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Sqlserver.java"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:14:24Z"