CVE-2024-46997: Dataease

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.

Affected products

  • Dataease Dataease: before 2.10.1 (fixed in 2.10.1)

Published 2024-09-23. Last modified 2026-06-17.