CVE-2024-29831: Apache DolphinScheduler: RCE by arbitrary js execution
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29831?
CVE-2024-29831 is considered a high severity vulnerability due to the ability for an authenticated user to execute arbitrary, unsandboxed JavaScript on the server.
How do I fix CVE-2024-29831?
To fix CVE-2024-29831, you should upgrade to Apache DolphinScheduler version 3.2.2 or later.
Who is affected by CVE-2024-29831?
CVE-2024-29831 affects users of Apache DolphinScheduler who utilize the switch task plugin.
What type of vulnerability is CVE-2024-29831?
CVE-2024-29831 is an improper input validation vulnerability.
Can CVE-2024-29831 be exploited remotely?
CVE-2024-29831 requires authentication, meaning it cannot be exploited by unauthenticated remote attackers.