Loading HuntDB...

GHSA-v7hg-77v9-2445

GitHub Security Advisory

Apache DolphinScheduler: Arbitrary js execute as root for authenticated users

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.

Users are recommended to upgrade to version 3.1.9, which fixes the issue.

Affected Packages

Maven org.apache.dolphinscheduler:dolphinscheduler-master
Affected versions: 0 (fixed in 3.1.9)

Related CVEs

Key Information

GHSA ID
GHSA-v7hg-77v9-2445
Published
December 30, 2023 6:30 PM
Last Modified
February 13, 2025 7:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.dolphinscheduler:dolphinscheduler-master
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.