CVE-2024-23320
Apache DolphinScheduler: Arbitrary js execution as root for authenticated users
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.
This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it.
This issue affects Apache DolphinScheduler: until 3.2.1.
Users are recommended to upgrade to version 3.2.1, which fixes the issue.
Vulnerabilidad de validación de entrada incorrecta en Apache DolphinScheduler. Un usuario autenticado puede hacer que se ejecute JavaScript arbitrario y sin espacio aislado en el servidor. Este problema es un legado de CVE-2023-49299. No lo solucionamos por completo en CVE-2023-49299 y agregamos un parche más para solucionarlo. Este problema afecta a Apache DolphinScheduler: hasta 3.2.1. Se recomienda a los usuarios actualizar a la versión 3.2.1, que soluciona el problema.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-01-15 CVE Reserved
- 2024-02-23 CVE Published
- 2024-02-24 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2024/02/23/3 | ||
https://lists.apache.org/thread/tnf99qoc6tlnwrny4t1zk6mfszgdsokm | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/apache/dolphinscheduler/pull/15487 | 2024-02-23 |
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/25qhfvlksozzp6j9y8ozznvjdjp3lxqq | 2024-02-23 | |
https://lists.apache.org/thread/p7rwzdgrztdfps8x1bwx646f1mn0x6cp | 2024-02-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache DolphinScheduler Search vendor "Apache Software Foundation" for product "Apache DolphinScheduler" | < 3.2.1 Search vendor "Apache Software Foundation" for product "Apache DolphinScheduler" and version " < 3.2.1" | en |
Affected
|