Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iiopname schemes. The vulnerability has been fixed in version 2.10.17.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64428.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-74"
]
}{
"cpe": "cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.17"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"54299001253208502209507063439663019187",
"298112220770250500095987880054148860191",
"72226076396926608174044731529434890760",
"179242353202582750976305644674258681125"
]
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/b7e585c1cc3fc2b73cb289b8680b4b3914be3d53",
"signature_type": "Line",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java"
},
"id": "CVE-2025-64428-cc215eeb",
"deprecated": false
}
]
"2026-07-16T00:38:18Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64428.json"