CVE Vulnerabilities

CVE-2020-11974

Published: Dec 18, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.

Affected Software

Name Vendor Start Version End Version
Dolphinscheduler Apache 1.2.0 (including) 1.2.0 (including)
Dolphinscheduler Apache 1.2.1 (including) 1.2.1 (including)

References