CVE-2024-29831

Severity
8.8HIGH
EPSS
0.3%
top 43.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

3
GHSA
Apache DolphinScheduler: RCE by arbitrary js execution2024-08-12
OSV
Apache DolphinScheduler: RCE by arbitrary js execution2024-08-12
CVEList
Apache DolphinScheduler: RCE by arbitrary js execution2024-08-09
CVE-2024-29831 (HIGH CVSS 8.8) | Improper Input Validation vulnerabi | cvebase.io