PT-2021-5482 · Apache · Apache Dolphinscheduler
Jinchen Sheng
·
Published
2021-01-11
·
Updated
2021-11-03
·
CVE-2021-27644
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache DolphinScheduler versions prior to 1.3.6
Description
The issue is related to errors in privilege management, allowing remote attackers to execute arbitrary SQL queries. Specifically, authorized users can use SQL injection in the data source center when using a MySQL data source with an internal login account password.
Recommendations
For versions prior to 1.3.6, update to version 1.3.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the data source center for MySQL data sources with internal login account passwords until the update is applied.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Dolphinscheduler