CVE-2024-23320

CVE-2024-23320: Apache DolphinScheduler: Arbitrary js execution as root for authenticated users

Vendor Apache Software Foundation
Product Apache DolphinScheduler
Weakness CWE-20 · Input validation
Published February 23, 2024
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it. This issue affects Apache DolphinScheduler: until 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue.

Key dates

Disclosure timeline

February 23, 2024 CVE published
February 13, 2025 Record updated