https://seclists.org/oss-sec/2024/q1/158: CVE-2024-23320: Apache DolphinScheduler: Arbitrary js execution as root for authenticated users
Published Feb 23, 2024
·Updated
Affected Software
1 affected component
Apache Dolphinscheduler<3.2.1
Frequently Asked Questions
1
What is the severity of CVE-2024-23320?
The severity of CVE-2024-23320 is classified as important.
2
What versions of Apache DolphinScheduler are affected by CVE-2024-23320?
CVE-2024-23320 affects Apache DolphinScheduler versions before 3.2.1.
3
How does CVE-2024-23320 impact authenticated users?
CVE-2024-23320 allows authenticated users to execute arbitrary, unsandboxed JavaScript on the server.
4
Is CVE-2024-23320 a new vulnerability?
No, CVE-2024-23320 is a legacy issue stemming from CVE-2023-49299.
5
How can I mitigate CVE-2024-23320 in my environment?
To mitigate CVE-2024-23320, upgrade to Apache DolphinScheduler version 3.2.1 or later.