Arbitrary JavaScript Execution Vulnerability Affects Apache DolphinScheduler
CVE-2024-29831
8.8HIGH
What is CVE-2024-29831?
An improper input validation vulnerability exists in Apache DolphinScheduler that allows authenticated users to execute arbitrary, unsandboxed JavaScript on the server. This can lead to severe security implications for affected systems. Users are advised to upgrade to version 3.2.2 or later, particularly if utilizing the switch task plugin, to ensure protection against potential exploits.
Affected Version(s)
Apache DolphinScheduler 0 <= 3.2.1