PT-2023-31159 · Apache · Apache Dolphinscheduler

Eluen Siebene

·

Published

2023-12-29

·

Updated

2025-03-18

·

CVE-2023-49299

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions prior to 3.1.9
Description The issue is related to an Improper Input Validation vulnerability, allowing an authenticated user to cause arbitrary, unsandboxed JavaScript to be executed on the server. This can lead to arbitrary code execution. The severity of this issue is marked as important.
Recommendations To resolve the issue, users are recommended to upgrade to version 3.1.9, which fixes the issue. As a temporary workaround, consider restricting access to sensitive areas of the server to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49299
GHSA-V7HG-77V9-2445

Affected Products

Apache Dolphinscheduler