Description
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
Remediation
References
http://www.openwall.com/lists/oss-security/2021/11/01/3
https://lists.apache.org/thread.html/r35d6acf021486a390a7ea09e6650c2fe19e72522bd484791d606a6e6%40%3Cdev.dolphinscheduler.apache.org%3E
https://lists.apache.org/thread.html/r35d6acf021486a390a7ea09e6650c2fe19e72522bd484791d606a6e6%40%3Cdev.dolphinscheduler.apache.org%3E
Related Vulnerabilities
CVE-2020-8175 Vulnerability in maven package org.webjars.npm:jpeg-js
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elastic-udfs-parent
CVE-2022-24897 Vulnerability in maven package org.xwiki.commons:xwiki-commons-velocity
CVE-2019-1003081 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer