dolphinschedulerGHSA-4vv4-crw4-8pcw
Apache DolphinScheduler: Resource File Read And Write Vulnerability
High8.1CVE-2024-30188 · Published Aug 12, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | >= 3.1.0, < 3.2.2 | 3.2.2 |
Details and references
File read and write vulnerability in Apache DolphinScheduler, authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- CVE-2024-30188
More dolphinscheduler advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 122024 | Apache DolphinScheduler: RCE by arbitrary js execution CVE-2024-29831High8.8fixed in 3.2.2 | High8.8 | 3.2.2 |
| Feb 202024 | Improper Certificate Validation in Apache DolphinScheduler CVE-2023-49250High7.3fixed in 3.2.1 | High7.3 | 3.2.1 |
| Feb 202024 | Arbitrary File Read Vulnerability in Apache Dolphinscheduler CVE-2023-51770High7.5fixed in 3.2.1 | High7.5 | 3.2.1 |
| Feb 202024 | Session Fixation Apache DolphinScheduler CVE-2023-50270Mediumfixed in 3.2.1 | Medium | 3.2.1 |
| Feb 202024 | Remote Code Execution in Apache Dolphinscheduler CVE-2023-49109Critical9.8fixed in 3.2.1 | Critical9.8 | 3.2.1 |
| Nov 242023 | Apache DolphinScheduler sensitive information disclosure CVE-2023-48796High7.5fixed in 3.0.2 | High7.5 | 3.0.2 |