CVE-2025-49001
moderateJWT Token Forgery Authentication Bypass in DataEase Before 2.10.10
CVE-2025-49001 is an improper authentication flaw (CWE-287) in DataEase, an open-source business intelligence and data visualization tool, where JWT secret verification fails to take effect in versions prior to 2.10.10. Because the server accepts tokens signed with any secret, an attacker can forge a JWT with an arbitrary signing key and have it accepted as valid, bypassing authentication; CVSS 4.0 scores this 7.7 (High) as network-exploitable with no privileges or user interaction required and a high integrity impact. A successful attacker can impersonate arbitrary users, including administrators, gaining unauthorized access to dashboards, connected data sources, and management functions. All DataEase deployments running versions prior to 2.10.10 are affected, with internet-exposed instances at the greatest risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 22.2% probability of exploitation within 30 days (98th percentile), indicating elevated risk.
What to do: Upgrade to DataEase 2.10.10 or later as soon as possible; no workarounds are available. Prioritize patching internet-facing instances, and review authentication and access logs for suspicious or anomalous JWT-based sessions indicating possible token forgery.
| DataEase | All versions prior to 2.10.10 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
- Vendors
- dataease
- Products
- dataease
- Weakness
- CWE-287
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.