First published: Tue Feb 20 2024(Updated: )
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.dolphinscheduler:dolphinscheduler | >=3.0.0<3.2.1 | 3.2.1 |
Apache DolphinScheduler | >=3.0.0 <3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49109 has been classified as a vulnerability that allows for remote code execution.
The recommended fix for CVE-2023-49109 is to upgrade Apache DolphinScheduler to version 3.2.1 or later.
CVE-2023-49109 affects Apache DolphinScheduler versions from 3.0.0 up to, but not including, 3.2.1.
CVE-2023-49109 can lead to unauthorized remote code execution, potentially compromising system integrity.
No official workaround has been documented for CVE-2023-49109; upgrading is the only recommended action.