https://seclists.org/oss-sec/2023/q4/347: CVE-2023-49299: Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
Published Dec 29, 2023
·Updated
Affected Software
1 affected component
Apache Dolphinscheduler<=3.1.9
Frequently Asked Questions
1
What is the severity of CVE-2023-49299?
The severity of CVE-2023-49299 is classified as important.
2
What versions of Apache DolphinScheduler are affected by CVE-2023-49299?
Apache DolphinScheduler versions through 3.1.9 are affected by CVE-2023-49299.
3
How do I fix CVE-2023-49299?
To fix CVE-2023-49299, upgrade Apache DolphinScheduler to the latest version that addresses this vulnerability.
4
What type of vulnerability is CVE-2023-49299?
CVE-2023-49299 is an Improper Input Validation vulnerability that allows arbitrary JavaScript execution.
5
Who can exploit CVE-2023-49299?
CVE-2023-49299 can be exploited by authenticated users of Apache DolphinScheduler.