CVE-2021-27644

In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-11-01 10:15

Updated : 2024-11-21 05:58


NVD link : CVE-2021-27644

Mitre link : CVE-2021-27644

CVE.ORG link : CVE-2021-27644


JSON object : View

Products Affected

apache

  • dolphinscheduler
CWE
CWE-264

Permissions, Privileges, and Access Controls

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')