Rewterz
Rewterz Threat Advisory – Multiple Adobe Dimension Vulnerabilities
December 31, 2023
Rewterz
Rewterz Threat Advisory – CVE-2023-40446 – Apple macOS Monterey Vulnerability
January 1, 2024

Rewterz Threat Advisory – CVE-2023-49299 – Apache DolphinScheduler Vulnerability

Severity

Medium

Analysis Summary

CVE-2023-49299

Apache DolphinScheduler could allow a remote authenticated attacker to execute arbitrary code on the system, caused by improper input validation. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary unsandboxed javascript on the server.

Impact

  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2023-49299

Affected Vendors

Apache

Affected Products

  • Apache DolphinScheduler 3.1.9

Remediation

Refer to Dolphinscheduler GIT Repository for patch, upgrade or suggested workaround information.

Dolphinscheduler GIT Repository