Description
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
Remediation
References
http://www.openwall.com/lists/oss-security/2021/11/01/3
https://lists.apache.org/thread.html/r35d6acf021486a390a7ea09e6650c2fe19e72522bd484791d606a6e6%40%3Cdev.dolphinscheduler.apache.org%3E
https://lists.apache.org/thread.html/r35d6acf021486a390a7ea09e6650c2fe19e72522bd484791d606a6e6%40%3Cdev.dolphinscheduler.apache.org%3E
Related Vulnerabilities
CVE-2020-6452 Vulnerability in npm package electron
CVE-2020-7777 Vulnerability in npm package jsen
CVE-2020-7629 Vulnerability in npm package install-package
CVE-2022-36272 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2018-19361 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind