An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.dataease:dataease-plugin-common(Maven) | 0 | 1.11.2 | N/A |
CVSS Metrics