Description
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
Remediation
References
http://www.openwall.com/lists/oss-security/2021/11/01/3
https://lists.apache.org/thread.html/r35d6acf021486a390a7ea09e6650c2fe19e72522bd484791d606a6e6%40%3Cdev.dolphinscheduler.apache.org%3E
https://lists.apache.org/thread.html/r35d6acf021486a390a7ea09e6650c2fe19e72522bd484791d606a6e6%40%3Cdev.dolphinscheduler.apache.org%3E
Related Vulnerabilities
CVE-2019-10282 Vulnerability in maven package hudson.plugins.klaros:klaros-testmanagement
CVE-2021-21118 Vulnerability in npm package electron
CVE-2023-48967 Vulnerability in maven package org.noear:solon.serialization.fury
CVE-2019-15478 Vulnerability in npm package status-board
CVE-2019-19771 Vulnerability in npm package wallet-address-vaildator