CVE-2021-27644: DolphinScheduler mysql jdbc connector parameters deserialize remote code execution
Published Nov 1, 2021
·Updated
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
Affected Software
1 affected component
Apache Dolphinscheduler<1.3.6
Event History
Nov 1, 2021
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-27644?
CVE-2021-27644 is a vulnerability in Apache DolphinScheduler versions before 1.3.6 that allows authorized users to use SQL injection in the data source center.
2
How severe is CVE-2021-27644?
CVE-2021-27644 has a severity score of 8.8 (high).
3
Which software versions are affected by CVE-2021-27644?
Apache DolphinScheduler versions up to exclusive 1.3.6 are affected by CVE-2021-27644.
4
What is the impact of CVE-2021-27644?
CVE-2021-27644 allows authorized users to perform SQL injection in the data source center, potentially compromising the integrity and confidentiality of the data.
5
Is there a fix available for CVE-2021-27644?
Yes, updating to Apache DolphinScheduler version 1.3.6 or later will mitigate the vulnerability.