CVE-2024-30269

CVSS V2 None CVSS V3 None
Description
DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform's database configuration is returned. The vulnerability has been fixed in v2.5.0. No known workarounds are available aside from upgrading.
Overview
  • CVE ID
  • CVE-2024-30269
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-08T14:19:56.293Z
  • Last Modified Date
  • 2024-04-08T14:19:56.293Z
History
Created Old Value New Value Data Type Notes
2024-06-26 11:30:01 Added to TrackCVE