Description
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
Remediation
References
https://lists.apache.org/thread.html/r35d6acf021486a390a7ea09e6650c2fe19e72522bd484791d606a6e6%40%3Cdev.dolphinscheduler.apache.org%3E
http://www.openwall.com/lists/oss-security/2021/11/01/3
Related Vulnerabilities
CVE-2022-45400 Vulnerability in maven package org.jvnet.hudson.plugins:japex
CVE-2023-24057 Vulnerability in maven package org.hl7.fhir.publisher:org.hl7.fhir.publisher.core
CVE-2023-37903 Vulnerability in maven package org.webjars.npm:vm2
CVE-2023-34062 Vulnerability in maven package io.projectreactor.netty:reactor-netty-http