Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
History

Tue, 18 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache dolphinscheduler
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache dolphinscheduler

Mon, 12 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 12 Aug 2024 18:30:00 +0000

Type Values Removed Values Added
References

Fri, 09 Aug 2024 14:45:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
Title Apache DolphinScheduler: RCE by arbitrary js execution
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-12T17:49:00.242Z

Reserved: 2024-03-20T09:51:46.246Z

Link: CVE-2024-29831

cve-icon Vulnrichment

Updated: 2024-08-09T15:02:51.385Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T13:38:18.560

Modified: 2025-03-18T15:56:38.357

Link: CVE-2024-29831

cve-icon Redhat

No data.