CVE-2023-49299
HIGH WAF: Medium
CVSS 8.8
Published: 2023-12-30
CWE-20 CWE-20
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue.
WAF Coverage Analysis
Improper Input Validation
Medium WAF Coverage
OWASP: A03:2021 Injection
920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection
Improper Input Validation
Medium WAF Coverage
OWASP: A03:2021 Injection
920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| apache | dolphinscheduler | up to 3.1.9 |
References
- www.openwall.com
- github.com (Patch, Vendor Advisory)
- lists.apache.org (Mailing List, Vendor Advisory)