CVE-2024-46997: Dataease
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.
Affected products
- Dataease Dataease: before 2.10.1 (fixed in 2.10.1)
Published 2024-09-23. Last modified 2026-06-17.