https://seclists.org/oss-sec/2024/q3/188: CVE-2024-30188: Apache DolphinScheduler: source File ad And Write Vulnerability
Published Aug 9, 2024
·Updated
Affected Software
1 affected component
Apache Dolphinscheduler<3.2.2
Frequently Asked Questions
1
What is the severity of CVE-2024-30188?
The severity of CVE-2024-30188 is classified as important.
2
Which versions of Apache DolphinScheduler are affected by CVE-2024-30188?
Apache DolphinScheduler versions from 3.1.0 before 3.2.2 are affected by CVE-2024-30188.
3
What is the main vulnerability described in CVE-2024-30188?
CVE-2024-30188 describes a file read and write vulnerability that allows authenticated users to access unauthorized resource files.
4
How do I fix CVE-2024-30188?
To fix CVE-2024-30188, upgrade Apache DolphinScheduler to version 3.2.2 or later.
5
Can unauthorized users exploit CVE-2024-30188?
No, only authenticated users can exploit the file read and write vulnerability in CVE-2024-30188.