CVE-2025-53006
CRITICALDescription
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality. The difference lies in that "sslfactory" and related parameters need to be triggered after establishing the connection. Other similar parameters include "sslhostnameverifier", "sslpasswordcallback", and "authenticationPluginClassName". This issue has been patched in 2.10.11.
Is your site exposed to CVE-2025-53006?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| dataease | dataease |
References
Frequently Asked Questions
What is CVE-2025-53006? +
How severe is CVE-2025-53006? +
What products are affected by CVE-2025-53006? +
How do I check if I'm vulnerable to CVE-2025-53006? +
Related Vulnerabilities
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take …
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability …
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 …
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution …
DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function …