PT-2023-31159 · Apache · Apache Dolphinscheduler

Eluen Siebene

·

Publicado

2023-12-29

·

Atualizado

2025-03-18

·

CVE-2023-49299

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions prior to 3.1.9
Description The issue is related to an Improper Input Validation vulnerability, allowing an authenticated user to cause arbitrary, unsandboxed JavaScript to be executed on the server. This can lead to arbitrary code execution. The severity of this issue is marked as important.
Recommendations To resolve the issue, users are recommended to upgrade to version 3.1.9, which fixes the issue. As a temporary workaround, consider restricting access to sensitive areas of the server to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49299
GHSA-V7HG-77V9-2445

Produtos afetados

Apache Dolphinscheduler