CVE-2025-53004

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/06/2025
Last modified:
10/07/2025

Description

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's Redshift Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has been patched in version 2.10.11.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:* 2.10.11 (excluding)