Skip to content
dolphinschedulerGHSA-4vv4-crw4-8pcw

Apache DolphinScheduler: Resource File Read And Write Vulnerability

High8.1CVE-2024-30188 · Published Aug 12, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.dolphinscheduler:dolphinscheduler
Maven
>= 3.1.0, < 3.2.23.2.2
Details and references

File read and write vulnerability in Apache DolphinScheduler, authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20
Also known as
CVE-2024-30188

More dolphinscheduler advisories

All
DateAdvisory
Aug 122024Apache DolphinScheduler: RCE by arbitrary js execution
CVE-2024-29831High8.8fixed in 3.2.2
Feb 202024Improper Certificate Validation in Apache DolphinScheduler
CVE-2023-49250High7.3fixed in 3.2.1
Feb 202024Arbitrary File Read Vulnerability in Apache Dolphinscheduler
CVE-2023-51770High7.5fixed in 3.2.1
Feb 202024Session Fixation Apache DolphinScheduler
CVE-2023-50270Mediumfixed in 3.2.1
Feb 202024Remote Code Execution in Apache Dolphinscheduler
CVE-2023-49109Critical9.8fixed in 3.2.1
Nov 242023Apache DolphinScheduler sensitive information disclosure
CVE-2023-48796High7.5fixed in 3.0.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.