CVE-2021-27644

Description

In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.092

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-27644 are fixed in Apache-dolphinscheduler-server 1.3.6Windows
Vulnerabilities CVE-2021-27644 are fixed in Apache-dolphinscheduler-server for Linux 1.3.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234