#VU126330 Improper Verification of Cryptographic Signature in DataEase - CVE-2024-47073
Published: November 7, 2024 / Updated: April 16, 2026
DataEase
DataEase
Description
The vulnerability allows a remote attacker to access arbitrary interfaces.
The vulnerability exists due to improper authentication in TokenUtils.userBOByToken when handling JWT-based authentication requests. A remote attacker can send a specially crafted request with a forged JWT token to access arbitrary interfaces.