DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker-controlled staticResource names and Base64 content, allowing path traversal and arbitrary file writes because only / was used when extracting the file name. This issue is fixed in version 2.10.23.
Security readout for executives and security teams
Plain-English summary
DataEase before 2.10.23 can let a logged-in attacker write files outside the intended template resource area. That can damage application integrity and availability, and may enable broader compromise depending on where files can be written.
Executive priority
Treat as high priority for DataEase environments. Patch promptly because exploitation requires only low privileges and can alter or disrupt server-side files.
Technical view
The vulnerable template save flow reaches TemplateManageService#save, StaticResourceServer#saveFilesToServe, and /de2api/templateManage/save with attacker-controlled staticResource names and Base64 content. Insufficient path handling, categorized as CWE-22, allows path traversal and arbitrary file writes. Fixed in 2.10.23.
Likely exposure
Organizations running DataEase versions earlier than 2.10.23 are exposed, especially where low-privileged authenticated users can access template management functionality over the network.
Exploitation context
The CVSS vector indicates network access, low privileges, no user interaction, and high integrity and availability impact. The provided sources do not show KEV listing or confirmed active exploitation.
Researcher notes
The key weakness is filename/path extraction that only handled /, allowing traversal through staticResource names. Evidence supports arbitrary file write before 2.10.23, but does not establish exploitation in the wild.
Mitigation direction
Upgrade DataEase to version 2.10.23 or later.
Review the GitHub advisory and release notes before rollout.
Inventory DataEase instances and identify versions below 2.10.23.
Restrict template management access to trusted users until patched.
Monitor for unexpected file changes in DataEase service directories.
Validation and detection
Confirm each DataEase instance version is 2.10.23 or later.
Check whether template management is reachable by low-privileged users.
Review logs for /de2api/templateManage/save activity.
Inspect recent template static resources for suspicious file paths.
Verify patch deployment through package, container, or release metadata.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-22: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
4Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-22 · source CWE mapping
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.