Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS05M2c0LTNwaGMtZzR4d80W0Q

SQL injection in Apache DolphinScheduler

In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)

Permalink: https://github.com/advisories/GHSA-93g4-3phc-g4xw
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05M2c0LTNwaGMtZzR4d80W0Q
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 2 years ago
Updated: over 1 year ago


CVSS Score: 8.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-93g4-3phc-g4xw, CVE-2021-27644
References: Blast Radius: 14.3

Affected Packages

maven:org.apache.dolphinscheduler:dolphinscheduler-server
Dependent packages: 8
Dependent repositories: 42
Downloads:
Affected Version Ranges: < 1.3.6
Fixed in: 1.3.6
All affected versions: 1.2.0, 1.2.1, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5
All unaffected versions: 1.3.6, 1.3.7, 1.3.8, 1.3.9, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.9, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.1.0