Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v7hg-77v9-2445

Опубликовано: 30 дек. 2023
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Apache DolphinScheduler: Arbitrary js execute as root for authenticated users

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.

Users are recommended to upgrade to version 3.1.9, which fixes the issue.

Пакеты

Наименование

org.apache.dolphinscheduler:dolphinscheduler-master

maven
Затронутые версииВерсия исправления

< 3.1.9

3.1.9

EPSS

Процентиль: 76%
0.00988
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue.

EPSS

Процентиль: 76%
0.00988
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-20