First published: Fri Dec 29 2023(Updated: )
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.dolphinscheduler:dolphinscheduler-master | <3.1.9 | 3.1.9 |
Apache DolphinScheduler | <3.1.9 | |
<3.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49299 is classified as a high severity vulnerability due to improper input validation allowing arbitrary JavaScript execution.
To fix CVE-2023-49299, upgrade Apache DolphinScheduler to version 3.1.9 or later.
CVE-2023-49299 affects authenticated users of Apache DolphinScheduler versions prior to 3.1.9.
CVE-2023-49299 is categorized as an improper input validation vulnerability.
Yes, CVE-2023-49299 can potentially lead to server compromise by allowing the execution of unsandboxed JavaScript.