CVE-2024-31441
DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in v1.18.19.
- Affected products
- Dataease
- Dataease
- < 1.18.19
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.6% (43th percentile)
- Weakness
- CWE-863
- NVD status
- Analyzed
- Published
- 2024-05-10
CVE-2024-31441 at NVD
No indexed exploits for CVE-2024-31441 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-31441 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.