CVE-2025-58748: Dataease Jdbc Url Scheme Not Validated
A DatasourceConfiguration subclass exposes getJdbc() that validates illegal URL parameter tokens but does not assert that the JDBC URL starts with the expected driver scheme prefix (e.g., "jdbc:h2"). Because the configuration's driver/URL fields are attacker-controllable, an attacker can substitute a different driver (e.g., com.amazon.redshift.jdbc42.Driver)
greprules fetch cve-2025-58748-dataease-jdbc-url-scheme-not-validated --engine opengrepDescription
A DatasourceConfiguration subclass exposes getJdbc() that validates illegal URL parameter tokens but does not assert that the JDBC URL starts with the expected driver scheme prefix (e.g., "jdbc:h2"). Because the configuration's driver/URL fields are attacker-controllable, an attacker can substitute a different driver (e.g., com.amazon.redshift.jdbc42.Driver)
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.