Опубликовано: 12 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8
Описание
Apache DolphinScheduler: RCE by arbitrary js execution
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
Пакеты
Наименование
org.apache.dolphinscheduler:dolphinscheduler
maven
Затронутые версииВерсия исправления
< 3.2.2
3.2.2
Связанные уязвимости
CVSS3: 8.8
nvd
больше 1 года назад
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.