DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so com.amazon.redshift.Driver#connect, com.amazon.redshift.Driver#getJdbcIniFile, and com.amazon.redshift.util.ObjectFactory#instantiate execute a reflection-based remote code execution chain during a normal JDBC connection through io.dataease.datasource.type.Redshift. This issue is fixed in version 2.10.23.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45534.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-94"
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"15821317397347673482983527820989049626",
"34777742503710241182623721919297647880",
"17358568406595948050264051915989166974",
"218444518956152575236350449743578772568"
]
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3e58149f1e014b1a7ae2c12134b37ae438f676ac",
"signature_type": "Line",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/CoreApplication.java"
},
"id": "CVE-2026-45534-0a848064",
"deprecated": false
},
{
"digest": {
"length": 141.0,
"function_hash": "113493415089312803196753409193036914026"
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3e58149f1e014b1a7ae2c12134b37ae438f676ac",
"signature_type": "Function",
"target": {
"function": "main",
"file": "core/core-backend/src/main/java/io/dataease/CoreApplication.java"
},
"id": "CVE-2026-45534-19abf907",
"deprecated": false
}
]
"2026-07-22T04:18:29Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45534.json"