DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps://. However, omission of protection for the dns:// protocol results in an SSRF vulnerability. This issue is fixed in version 2.10.15.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-918"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64163.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.15"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64163.json"
[
{
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Oracle.java"
},
"id": "CVE-2025-64163-22adc809",
"digest": {
"threshold": 0.9,
"line_hashes": [
"75172544114056436429415801211518966694",
"251805794178485281378901353911054063147",
"47358127725463354352068734561596955717",
"330285601023911375650212228627667421111",
"209829719789645804566225654189757887937",
"241075840831451737810488679501752633791",
"129823586394974091918893571244418363260",
"128789957289550124868612299009705535605",
"204433914157597240503199873817420693623",
"241411314238306039630445652068988046157",
"67362837996066895491036262167965060049",
"68233504285946658082638931608295824211"
]
},
"deprecated": false,
"source": "https://github.com/dataease/dataease/commit/869b7fb8b10069ac6c326554bfa8f060a539ba85"
},
{
"signature_version": "v1",
"signature_type": "Function",
"target": {
"function": "getJdbc",
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Oracle.java"
},
"id": "CVE-2025-64163-5d1e0c85",
"digest": {
"function_hash": "289650662687262343518419251753828532",
"length": 825.0
},
"deprecated": false,
"source": "https://github.com/dataease/dataease/commit/869b7fb8b10069ac6c326554bfa8f060a539ba85"
},
{
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java"
},
"id": "CVE-2025-64163-deb635da",
"digest": {
"threshold": 0.9,
"line_hashes": [
"318129256003586163354486806924572309333",
"113275257203713162799119557480857899533",
"94725240253240248932332887136469542976",
"237077899278387774637369020808616136867"
]
},
"deprecated": false,
"source": "https://github.com/dataease/dataease/commit/869b7fb8b10069ac6c326554bfa8f060a539ba85"
}
]
"2026-07-15T20:54:34Z"