Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache DolphinScheduler: Arbitrary js execution as root for authenticated users
Vulnerability Description
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it. This issue affects Apache DolphinScheduler: until 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Apache DolphinScheduler 输入验证错误漏洞
Vulnerability Description
Apache DolphinScheduler是美国阿帕奇(Apache)基金会的一个分布式的基于DAG可视化的工作流任务调度系统。 Apache DolphinScheduler 3.2.1之前版本存在输入验证错误漏洞,该漏洞源于存在不正确的输入验证漏洞,经过身份验证的用户可能会在服务器上执行任意的、未沙盒化的JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A