First published: Fri Dec 18 2020(Updated: )
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache DolphinScheduler | =1.2.0 | |
Apache DolphinScheduler | =1.2.1 | |
maven/org.apache.dolphinscheduler:dolphinscheduler | <1.3.0 | 1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11974 is a remote code execution vulnerability in DolphinScheduler 1.2.0 and 1.2.1 when using mysql connectorj with mysql as the database.
CVE-2020-11974 has a severity rating of 9.8, which is considered critical.
CVE-2020-11974 affects DolphinScheduler versions 1.2.0 and 1.2.1.
To fix CVE-2020-11974, you should upgrade to a version of DolphinScheduler that is not affected by this vulnerability.
You can find more information about CVE-2020-11974 in the Apache DolphinScheduler mailing list threads provided in the references.