https://seclists.org/oss-sec/2024/q3/187: CVE-2024-29831: Apache DolphinScheduler: RCE by arbitrary js execution
Published Aug 9, 2024
·Updated
Affected Software
1 affected component
Apache Dolphinscheduler<3.2.1
Frequently Asked Questions
1
What is the severity of CVE-2024-29831?
CVE-2024-29831 has a moderate severity rating.
2
How do I fix CVE-2024-29831?
To fix CVE-2024-29831, update Apache DolphinScheduler to version 3.2.2 or later.
3
What versions of Apache DolphinScheduler are affected by CVE-2024-29831?
CVE-2024-29831 affects Apache DolphinScheduler versions up to and including 3.2.1.
4
What type of vulnerability is CVE-2024-29831?
CVE-2024-29831 is an improper input validation vulnerability that allows remote code execution via arbitrary JavaScript.
5
Who can exploit CVE-2024-29831?
An authenticated user can exploit CVE-2024-29831 to execute arbitrary, unsandboxed JavaScript on the server.