S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-30269 Scanner

CVE-2024-30269 Scanner - Information Disclosure vulnerability in DataEase

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-30269
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform's database configuration is returned. The vulnerability has been fixed in v2.5.0. No known workarounds are available aside from upgrading.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
dataeaseby dataease
< 2.5.0
dataeaseby dataease
AFFECTED< 2.5.0SAFE ✓≥ 2.5.0
Updated Sep 10, 2026View on NVD →
Detail

DataEase is an open-source data visualization and analysis tool used for processing and presenting data in an intuitive manner. Businesses, developers, and analysts worldwide leverage DataEase to streamline their data workflow and gain insightful analytics. It supports various types of data inputs, enabling users to connect databases and build visualizations directly from said data. The tool’s flexibility and open-source nature allow for community contributions and enhancements, making it adaptable to a wide range of applications. However, being a highly-accessible application, it must ensure stringent security measures to protect data confidentiality. Due to its integrations and broad use, maintaining its security is crucial to preventing potential vulnerabilities that could jeopardize sensitive information.

The Information Disclosure vulnerability detected in DataEase affects its ability to secure configuration details of connected databases. Specifically, this issue arises in versions up to 2.4.1, where sensitive details such as database credentials can be accessed through specific endpoints. This unintentional exposure of internal configurations provides unauthorized entities with sensitive information that may be exploited. The impact level of this vulnerability is categorized as medium, as it affects confidentiality, opening pathways to further security breaches if exploited. Hence, addressing such vulnerabilities is vital for the continued trust and security of the platform’s user base.

Technical details of the vulnerability indicate that the exposure occurs when accessing the endpoint `/de2api/engine/getEngine;.js` through a browser. This endpoint inadvertently returns application configuration data, including usernames, passwords, port numbers, and process IDs. These parameters form the backbone of the database connection, meaning unauthorized access can compromise the entire system's integrity. The vulnerability exploits insufficient access controls that fail to protect sensitive fields in responses delivered through this endpoint. Despite requiring no prior authentication to exploit, the vulnerability is contained to specific application functionalities, which is a notable security threat to data protection.

When exploited, the Information Disclosure vulnerability could lead to unauthorized access to sensitive information, with potential cascading effects. Malicious actors can leverage these credentials to access the database, alter data, or even exfiltrate sensitive data that might reside within. System integrity and confidentiality could be compromised, potentially resulting in significant data breaches. Moreover, this could allow attackers to map other vulnerabilities or use compromised credentials to infiltrate deeper layers of an organization's IT infrastructure.

REFERENCES

Solution Advice
  • Upgrade DataEase to version 2.5.0 or later, where the vulnerability is patched.
  • Implement strict access control on sensitive endpoints to ensure only authorized users have access.
  • Regularly audit and test all application endpoints for potential information leaks.
  • Employ data encryption and obfuscation techniques to protect sensitive configuration data.
  • Ensure that server response headers do not expose unnecessary information to end-users.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-30269 Scanner - Information Disclosure vulnerability in DataEase | S4E