Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m9q4-p56m-mc6q Apache DolphinScheduler: RCE by arbitrary js execution
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 19 Mar 2025 01:15:00 +0900

Type Values Removed Values Added
First Time appeared Apache
Apache dolphinscheduler
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache dolphinscheduler

Tue, 13 Aug 2024 04:00:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 13 Aug 2024 03:30:00 +0900

Type Values Removed Values Added
References

Fri, 09 Aug 2024 23:45:00 +0900

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
Title Apache DolphinScheduler: RCE by arbitrary js execution
Weaknesses CWE-20
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-12T17:49:00.242Z

Reserved: 2024-03-20T09:51:46.246Z

Link: CVE-2024-29831

cve-icon Vulnrichment

Updated: 2024-08-09T15:02:51.385Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T13:38:18.560

Modified: 2025-03-18T15:56:38.357

Link: CVE-2024-29831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses