Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2024/08/09/6 | Mailing List Third Party Advisory |
https://lists.apache.org/thread/x1ch0x5om3srtbnp7rtsvdszho3mdrq0 | Vendor Advisory |
Configurations
History
18 Mar 2025, 15:56
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () https://lists.apache.org/thread/x1ch0x5om3srtbnp7rtsvdszho3mdrq0 - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* | |
First Time |
Apache dolphinscheduler
Apache |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
12 Aug 2024, 13:41
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-12 13:38
Updated : 2025-03-18 15:56
NVD link : CVE-2024-29831
Mitre link : CVE-2024-29831
JSON object : View
Products Affected
apache
- dolphinscheduler
CWE