Skip to content
dolphinschedulerGHSA-m9q4-p56m-mc6q

Apache DolphinScheduler: RCE by arbitrary js execution

High8.8CVE-2024-29831 · Published Aug 12, 2024 · updated Mar 19, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.dolphinscheduler:dolphinscheduler
Maven
< 3.2.23.2.2
Details and references

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20
Also known as
CVE-2024-29831

More dolphinscheduler advisories

All
DateAdvisory
Aug 122024Apache DolphinScheduler: Resource File Read And Write Vulnerability
CVE-2024-30188High8.1fixed in 3.2.2
Feb 202024Improper Certificate Validation in Apache DolphinScheduler
CVE-2023-49250High7.3fixed in 3.2.1
Feb 202024Arbitrary File Read Vulnerability in Apache Dolphinscheduler
CVE-2023-51770High7.5fixed in 3.2.1
Feb 202024Session Fixation Apache DolphinScheduler
CVE-2023-50270Mediumfixed in 3.2.1
Feb 202024Remote Code Execution in Apache Dolphinscheduler
CVE-2023-49109Critical9.8fixed in 3.2.1
Nov 242023Apache DolphinScheduler sensitive information disclosure
CVE-2023-48796High7.5fixed in 3.0.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.