CRITICAL 9.8 Maven
Remote Code Execution in Apache Dolphinscheduler
GHSA-qwxx-xww6-8q8m · CVE-2023-49109
Published · Modified
Description
This issue affects Apache DolphinScheduler 3.0.0 before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-49109
- WEB https://github.com/apache/dolphinscheduler/pull/14991
- PACKAGE https://github.com/apache/dolphinscheduler
- WEB https://lists.apache.org/thread/5b6yq2gov0fsy9x5dkvo8ws4rr45vkn8
- WEB https://lists.apache.org/thread/6kgsl93vtqlbdk6otttl0d8wmlspk0m5
- WEB http://www.openwall.com/lists/oss-security/2024/02/20/4
Ready to move
Start Securing
Free, no credit card | First findings in minutes