CVE-2023-49299: Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.
Users are recommended to upgrade to version 3.1.9, which fixes the issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49299?
CVE-2023-49299 is classified as a high severity vulnerability due to improper input validation allowing arbitrary JavaScript execution.
How do I fix CVE-2023-49299?
To fix CVE-2023-49299, upgrade Apache DolphinScheduler to version 3.1.9 or later.
Who is affected by CVE-2023-49299?
CVE-2023-49299 affects authenticated users of Apache DolphinScheduler versions prior to 3.1.9.
What type of vulnerability is CVE-2023-49299?
CVE-2023-49299 is categorized as an improper input validation vulnerability.
Can CVE-2023-49299 lead to a server compromise?
Yes, CVE-2023-49299 can potentially lead to server compromise by allowing the execution of unsandboxed JavaScript.