Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rc6h-qwj9-2c53

Опубликовано: 23 фев. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed JavaScript to be executed on the server.

This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it.

This issue affects Apache DolphinScheduler: until 3.2.1.

Users are recommended to upgrade to version 3.2.1, which fixes the issue.

Пакеты

Наименование

org.apache.dolphinscheduler:dolphinscheduler-master

maven
Затронутые версииВерсия исправления

< 3.2.1

3.2.1

EPSS

Процентиль: 72%
0.00736
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
nvd
почти 2 года назад

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it. This issue affects Apache DolphinScheduler: until 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue.

EPSS

Процентиль: 72%
0.00736
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-20