ZeroHour

CVE-2025-49001

moderate

JWT Token Forgery Authentication Bypass in DataEase Before 2.10.10

CVSS 4.0
7.7 high
EPSS
22%p98
Published
()
Modified
AI analysis

CVE-2025-49001 is an improper authentication flaw (CWE-287) in DataEase, an open-source business intelligence and data visualization tool, where JWT secret verification fails to take effect in versions prior to 2.10.10. Because the server accepts tokens signed with any secret, an attacker can forge a JWT with an arbitrary signing key and have it accepted as valid, bypassing authentication; CVSS 4.0 scores this 7.7 (High) as network-exploitable with no privileges or user interaction required and a high integrity impact. A successful attacker can impersonate arbitrary users, including administrators, gaining unauthorized access to dashboards, connected data sources, and management functions. All DataEase deployments running versions prior to 2.10.10 are affected, with internet-exposed instances at the greatest risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 22.2% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

What to do: Upgrade to DataEase 2.10.10 or later as soon as possible; no workarounds are available. Prioritize patching internet-facing instances, and review authentication and access logs for suspicious or anomalous JWT-based sessions indicating possible token forgery.

Affected
DataEaseAll versions prior to 2.10.10
Estimated exposure
moderatelikely tens of thousands of self-hosted instances, of which several thousand may be internet-exposed — DataEase is a widely adopted open-source BI and visualization platform with a substantial self-hosted installed base, but no authoritative install-count or internet-exposure scan data was provided, so this is an order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

Vendors
dataease
Products
dataease
Weakness
CWE-287
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.