dolphinschedulerGHSA-m9q4-p56m-mc6q
Apache DolphinScheduler: RCE by arbitrary js execution
High8.8CVE-2024-29831 · Published Aug 12, 2024 · updated Mar 19, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | < 3.2.2 | 3.2.2 |
Details and references
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- CVE-2024-29831
More dolphinscheduler advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 122024 | Apache DolphinScheduler: Resource File Read And Write Vulnerability CVE-2024-30188High8.1fixed in 3.2.2 | High8.1 | 3.2.2 |
| Feb 202024 | Improper Certificate Validation in Apache DolphinScheduler CVE-2023-49250High7.3fixed in 3.2.1 | High7.3 | 3.2.1 |
| Feb 202024 | Arbitrary File Read Vulnerability in Apache Dolphinscheduler CVE-2023-51770High7.5fixed in 3.2.1 | High7.5 | 3.2.1 |
| Feb 202024 | Session Fixation Apache DolphinScheduler CVE-2023-50270Mediumfixed in 3.2.1 | Medium | 3.2.1 |
| Feb 202024 | Remote Code Execution in Apache Dolphinscheduler CVE-2023-49109Critical9.8fixed in 3.2.1 | Critical9.8 | 3.2.1 |
| Nov 242023 | Apache DolphinScheduler sensitive information disclosure CVE-2023-48796High7.5fixed in 3.0.2 | High7.5 | 3.0.2 |