CVE-2025-70829
Received
Received - Intake
Information Exposure in Datart v1.0.0-rc.3 via H2 JDBC String
Publication date: 2026-02-17
Last updated on: 2026-02-23
Assigner: MITRE
Description
Description
An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| running-elephant | datart | 1.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |