DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker can construct a malicious tableName parameter to execute arbitrary SQL commands. This issue is fixed in version 2.10.14. No known workarounds exist.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62422.json",
"cwe_ids": [
"CWE-89"
]
}{
"cpe": "cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.14"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-12T15:14:24Z"
[
{
"source": "https://github.com/dataease/dataease/commit/3c52cc26c4cca1000294346cf99a84b25d38bfb2",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/provider/EsProvider.java"
},
"signature_version": "v1",
"id": "CVE-2025-62422-44ead14d",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"278649040579497352690219774147574748582",
"21517977259992985740294519465685864208",
"235029491719713419662029449727939408152",
"327322866339493478115278610752858982422"
]
}
},
{
"source": "https://github.com/dataease/dataease/commit/3c52cc26c4cca1000294346cf99a84b25d38bfb2",
"target": {
"function": "fetchTableField",
"file": "core/core-backend/src/main/java/io/dataease/datasource/provider/EsProvider.java"
},
"signature_version": "v1",
"id": "CVE-2025-62422-e504e097",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "285748931654222377944885954360693921965",
"length": 384.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62422.json"