ataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality. The difference lies in that "sslfactory" and related parameters need to be triggered after establishing the connection. Other similar parameters include "sslhostnameverifier", "sslpasswordcallback", and "authenticationPluginClassName". This issue has been patched in 2.10.11.
| Link | Resource |
|---|---|
| https://github.com/dataease/dataease/security/advisories/GHSA-q726-5pr9-x7gm | Exploit Vendor Advisory |
10 Jul 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Dataease dataease
Dataease |
|
| References | () https://github.com/dataease/dataease/security/advisories/GHSA-q726-5pr9-x7gm - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
03 Jul 2025, 15:13
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
02 Jul 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-07-02 15:15
Updated : 2025-07-10 15:16
NVD link : CVE-2025-53006
Mitre link : CVE-2025-53006
CVE.ORG link : CVE-2025-53006
JSON object : View
Improper Neutralization of Substitution Characters