CVE-2023-49299

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
30/12/2023
Last modified:
13/02/2025

Description

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* 3.1.9 (excluding)