Description
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket, allowing unauthenticated attackers who know a protected share UUID to obtain a valid link token for subsequent share-related API calls even with missing or invalid credentials. This issue is fixed in version 2.10.24.
Severity (CVSS)
| Base score | 8.7 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-863 — CWE-863: Incorrect Authorization
Affected products
| Vendor | Product | Versions |
|---|---|---|
| dataease | dataease | < 2.10.24 |
References
- https://github.com/dataease/dataease/security/advisories/GHSA-7287-qqj9-phr6 (x_refsource_CONFIRM)
- https://github.com/dataease/dataease/commit/c4e85a981e53c95b1ea73757db31e3025efdc410 (x_refsource_MISC)
- https://github.com/dataease/dataease/releases/tag/v2.10.24 (x_refsource_MISC)
Generated from the official CVE List on 08 Jul 2026 07:00 UTC.