#VU126332 Improper access control in DataEase - CVE-2024-56511
Published: January 10, 2025 / Updated: April 16, 2026
DataEase
DataEase
Description
The vulnerability allows a remote attacker to gain unauthorized access to protected interfaces.
The vulnerability exists due to improper access control in the io.dataease.auth.filter.TokenFilter class when handling crafted request URLs. A remote attacker can send a specially crafted request path to gain unauthorized access to protected interfaces.
Exploitation requires the application to be deployed with server.servlet.context-path configured.