CVE-2023-49299
Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue.
Vulnerabilidad de validación de entrada incorrecta en Apache DolphinScheduler. Un usuario autenticado puede hacer que se ejecute javascript arbitrario y sin espacio aislado en el servidor. Este problema afecta a Apache DolphinScheduler: hasta 3.1.9. Se recomienda a los usuarios actualizar a la versión 3.1.9, que soluciona el problema.
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-11-26 CVE Reserved
- 2023-12-30 CVE Published
- 2025-02-13 CVE Updated
- 2025-04-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2024/02/23/3 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/apache/dolphinscheduler/pull/15228 | 2024-02-23 |
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/tnf99qoc6tlnwrny4t1zk6mfszgdsokm | 2024-02-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Dolphinscheduler Search vendor "Apache" for product "Dolphinscheduler" | < 3.1.9 Search vendor "Apache" for product "Dolphinscheduler" and version " < 3.1.9" | - |
Affected
|