{"id":"GHSA-qwxx-xww6-8q8m","summary":"Remote Code Execution in Apache Dolphinscheduler","details":"This issue affects Apache DolphinScheduler 3.0.0 before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.  ","aliases":["CVE-2023-49109"],"modified":"2024-08-27T14:33:53.805475Z","published":"2024-02-20T12:30:58Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-02-21T00:17:58Z","nvd_published_at":"2024-02-20T10:15:07Z","cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49109"},{"type":"WEB","url":"https://github.com/apache/dolphinscheduler/pull/14991"},{"type":"PACKAGE","url":"https://github.com/apache/dolphinscheduler"},{"type":"WEB","url":"https://lists.apache.org/thread/5b6yq2gov0fsy9x5dkvo8ws4rr45vkn8"},{"type":"WEB","url":"https://lists.apache.org/thread/6kgsl93vtqlbdk6otttl0d8wmlspk0m5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/02/20/4"}],"affected":[{"package":{"name":"org.apache.dolphinscheduler:dolphinscheduler","ecosystem":"Maven","purl":"pkg:maven/org.apache.dolphinscheduler/dolphinscheduler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.2.1"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","3.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-qwxx-xww6-8q8m/GHSA-qwxx-xww6-8q8m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}