CVE-2024-47073
DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any interface. The vulnerability has been fixed in v2.10.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
- Affected products
- Dataease
- Dataease
- < 2.10.2
- Fix
- Available
- CVSS 4.0
- 9.3 CRITICAL
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-347
- NVD status
- Analyzed
- Published
- 2024-11-07
CVE-2024-47073 at NVD
No indexed exploits for CVE-2024-47073 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-47073 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.