High severity8.8NVD Advisory· Published Aug 12, 2024· Updated Jun 17, 2026
CVE-2024-29831
CVE-2024-29831
Description
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.dolphinscheduler:dolphinschedulerMaven | < 3.2.2 | 3.2.2 |
Affected products
3cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*range: <3.2.2
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2024/08/09/6nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-m9q4-p56m-mc6qghsaADVISORY
- lists.apache.org/thread/x1ch0x5om3srtbnp7rtsvdszho3mdrq0nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-29831ghsaADVISORY
News mentions
0No linked articles in our index yet.