VDB
Sign up
CRITICAL9.8

GHSA-2fm6-mv57-p2qh

Apache Dolphinscheduler Code Injection vulnerability

Quick fix

GHSA-2fm6-mv57-p2qh — org.apache.dolphinscheduler:dolphinscheduler-task-api: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.2.2</version> for org.apache.dolphinscheduler:dolphinscheduler-task-api

Details

Exposure of Remote Code Execution in Apache Dolphinscheduler.

This issue affects Apache DolphinScheduler: before 3.2.2.

We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.dolphinscheduler:dolphinscheduler-task-api
Introduced in: 3.1.0Fixed in: 3.2.2
Fix# pom.xml: bump <version>3.2.2</version> for org.apache.dolphinscheduler:dolphinscheduler-task-api

References