CVE-2023-49299
published 2023-12-30CVE-2023-49299: Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.42%
69.7th percentile
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.
Users are recommended to upgrade to version 3.1.9, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | dolphinscheduler | < 3.1.9 | 3.1.9 |
| apache | dolphinscheduler | < 3.2.1 | 3.2.1 |
| apache_software_foundation | apache_dolphinscheduler | < 3.2.1 | 3.2.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users
osv·2024-02-23·CVSS 8.8
CVE-2024-23320 [HIGH] Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users
Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed JavaScript to be executed on the server.
This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it.
This issue affects Apache DolphinScheduler: until 3.2.1.
Users are recommended to upgrade to version 3.2.1, which fixes the issue.
GHSA
Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users
ghsa·2024-02-23·CVSS 8.8
CVE-2024-23320 [HIGH] CWE-20 Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users
Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed JavaScript to be executed on the server.
This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it.
This issue affects Apache DolphinScheduler: until 3.2.1.
Users are recommended to upgrade to version 3.2.1, which fixes the issue.
GHSA
Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
ghsa·2023-12-30
CVE-2023-49299 [HIGH] CWE-20 Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.
Users are recommended to upgrade to version 3.1.9, which fixes the issue.
OSV
Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
osv·2023-12-30
CVE-2023-49299 [HIGH] Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.
Users are recommended to upgrade to version 3.1.9, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/02/23/3https://github.com/apache/dolphinscheduler/pull/15228https://lists.apache.org/thread/tnf99qoc6tlnwrny4t1zk6mfszgdsokmhttp://www.openwall.com/lists/oss-security/2024/02/23/3https://github.com/apache/dolphinscheduler/pull/15228https://lists.apache.org/thread/tnf99qoc6tlnwrny4t1zk6mfszgdsokm
2023-12-30
Published