Skip to main content
Vulnerability Database/CVE-2025-10770

CVE-2025-10770: Jeecg JimuReport Deserialization RCE Flaw

CVE-2025-10770 is a deserialization remote code execution vulnerability in Jeecg JimuReport affecting versions up to 2.1.2. Attackers can exploit the MySQL JDBC handler to execute arbitrary code. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2025-10770 Overview

A deserialization vulnerability affects jeecgboot JimuReport through version 2.1.2. The flaw resides in the MySQL JDBC Handler component, specifically in the /drag/onlDragDataSource/testConnection endpoint. Attackers can trigger insecure deserialization by manipulating input data sent to this endpoint. The issue is exploitable remotely and requires low privileges. Public exploit details have been disclosed through the vendor's GitHub issue tracker and VulDB.

Critical Impact

Authenticated remote attackers can abuse the JDBC data source test endpoint to trigger deserialization of attacker-controlled data, enabling limited compromise of confidentiality, integrity, and availability within the JimuReport instance.

Affected Products

  • jeecgboot JimuReport versions up to and including 2.1.2
  • Deployments exposing the /drag/onlDragDataSource/testConnection endpoint
  • Applications embedding the vulnerable MySQL JDBC Handler component

Discovery Timeline

  • 2025-09-21 - CVE-2025-10770 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-10770

Vulnerability Analysis

JimuReport is an open-source reporting and dashboard tool built on the Jeecg-Boot framework. The /drag/onlDragDataSource/testConnection endpoint validates data source connectivity for user-configured JDBC targets. The endpoint accepts connection parameters that flow into the MySQL JDBC handler without sufficient validation. Attacker-controlled input reaches a deserialization sink, aligning with weaknesses classified as [CWE-20] Improper Input Validation and [CWE-502] Deserialization of Untrusted Data. Because the exploit has been publicly disclosed, defenders should assume opportunistic scanning against exposed instances.

Root Cause

The endpoint constructs a JDBC connection using attacker-supplied host, port, and JDBC URL parameters. MySQL Connector/J supports properties such as autoDeserialize and queryInterceptors that can invoke Java deserialization when a malicious database server returns crafted responses. JimuReport does not sanitize or restrict these JDBC URL parameters before invoking the connection test.

Attack Vector

An authenticated user with low privileges sends a crafted POST request to /drag/onlDragDataSource/testConnection referencing an attacker-controlled MySQL server. When JimuReport attempts to connect, the rogue MySQL server responds with a serialized Java payload. The client-side JDBC driver deserializes the payload, executing gadget chains available on the JimuReport classpath. Public disclosure resides in the vendor's GitHub Issue Discussion and the VulDB entry #325126.

No verified exploit code is published in this advisory. Refer to the linked GitHub issue and VulDB entry for reproduction details.

Detection Methods for CVE-2025-10770

Indicators of Compromise

  • HTTP requests to /drag/onlDragDataSource/testConnection referencing external or unexpected MySQL host addresses
  • JDBC URL parameters containing autoDeserialize=true, queryInterceptors, statementInterceptors, or detectCustomCollations=true
  • Outbound connections from JimuReport application servers to untrusted MySQL endpoints on TCP/3306 or non-standard ports
  • Java stack traces referencing com.mysql.cj.jdbc deserialization frames in application logs

Detection Strategies

  • Inspect web access logs and WAF telemetry for POST requests to the vulnerable endpoint that originate from low-privileged sessions
  • Alert on JDBC connection strings submitted by users that include serialization-related properties
  • Monitor JVM behavior for unexpected child process creation or reflective class loading following requests to testConnection

Monitoring Recommendations

  • Deploy egress filtering that restricts JimuReport application servers to approved database hosts only
  • Enable audit logging on the onlDragDataSource controller and forward logs to a centralized analytics platform
  • Track user activity to correlate data source configuration changes with subsequent outbound network events

How to Mitigate CVE-2025-10770

Immediate Actions Required

  • Restrict access to the JimuReport administrative and data source configuration endpoints to trusted operators only
  • Place JimuReport behind authenticated network segmentation and disallow direct internet exposure
  • Block outbound TCP connections from application servers to arbitrary MySQL hosts using firewall or service mesh policies
  • Review recent data source configurations and audit logs for suspicious JDBC URLs

Patch Information

At the time of publication, no fixed version is referenced in NVD for CVE-2025-10770. Track the GitHub Issue Discussion for vendor remediation updates and upgrade guidance from jeecgboot.

Workarounds

  • Enforce an allow-list of permitted database hosts within JimuReport data source configurations
  • Sanitize or reject JDBC URL parameters such as autoDeserialize, queryInterceptors, and statementInterceptors before invoking a connection test
  • Run JimuReport with the least-privileged Java security manager profile and remove unnecessary gadget-chain libraries from the classpath where feasible
  • Remove or disable the /drag/onlDragDataSource/testConnection endpoint via reverse proxy rules if the drag-drop data source feature is not required
bash
# Example reverse proxy rule to block the vulnerable endpoint
location ~* /drag/onlDragDataSource/testConnection {
    deny all;
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.