Beveiligingsadvies

CVE-2026-23958

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-22 01:42:11
Laatst bijgewerkt 2026-01-26 16:18:33
Toegewezen door GitHub_M
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force the admin’s password by exploiting unmonitored API endpoints that verify JWT tokens. The vulnerability has been fixed in v2.10.19. No known workarounds are available.