CVE-2024-47073 is a critical vulnerability affecting DataEase, an open-source data visualization tool, specifically versions prior to 2.10.2. The flaw stems from a lack of JWT signature verification, enabling unauthenticated attackers to forge JWTs and gain unauthorized access to any interface. With a CVSS score of 9.1 (Critical), this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality and integrity. While not yet in CISA's KEV catalog, public Nuclei templates exist for exploitation, and its high EPSS score indicates a significant probability of future exploitation, though there is currently no widespread community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.10.2CPE matchmatch criteria | cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.