QID 980231
QID 980231: Java (maven) Security Update for org.apache.dolphinscheduler:dolphinscheduler-server (GHSA-93g4-3phc-g4xw)
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-93g4-3phc-g4xw for updates pertaining to this vulnerability.
Vendor References
- GHSA-93g4-3phc-g4xw -
github.com/advisories/GHSA-93g4-3phc-g4xw
CVEs related to QID 980231
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-93g4-3phc-g4xw | org.apache.dolphinscheduler:dolphinscheduler-server |
|