CVE-2024-31441

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in v1.18.19.

🔥 人人可用的开源 BI 工具,数据可视化神器。An open-source BI tool alternative to Tableau.
GitHubGitHub
24K