Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/x1ch0x5om3srtbnp7rtsvdszho3mdrq0 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2024/08/09/6 | Mailing List Third Party Advisory |
Configurations
History
18 Mar 2025, 15:56
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
First Time |
Apache
Apache dolphinscheduler |
|
References | () https://lists.apache.org/thread/x1ch0x5om3srtbnp7rtsvdszho3mdrq0 - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2024/08/09/6 - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* |
21 Nov 2024, 09:08
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary |
|
12 Aug 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
12 Aug 2024, 13:41
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-12 13:38
Updated : 2025-03-18 15:56
NVD link : CVE-2024-29831
Mitre link : CVE-2024-29831
CVE.ORG link : CVE-2024-29831
JSON object : View
Products Affected
apache
- dolphinscheduler
CWE