First published: Fri Aug 09 2024(Updated: )
File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.dolphinscheduler:dolphinscheduler | >=3.1.0<3.2.2 | 3.2.2 |
Apache DolphinScheduler | >=3.1.0<3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-30188 is considered to be significant due to potential unauthorized access to resource files by authenticated users.
To fix CVE-2024-30188, users should upgrade to Apache DolphinScheduler version 3.2.2 or later.
CVE-2024-30188 affects authenticated users of Apache DolphinScheduler versions from 3.1.0 up to but not including 3.2.2.
CVE-2024-30188 is related to file read and write vulnerabilities that allow unauthorized file access.
The potential impacts of CVE-2024-30188 include unauthorized access to sensitive resource files that could compromise system integrity.