CVE-2020-11974
CRITICALApache DolphinScheduler 1.2.0-1.2.1 - Remote Code Execution via MySQL ConnectorJ
Title source: llmDescription
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.
References (6)
Core 6
Core References
Mailing List mailing-list
https://lists.apache.org/thread.html/ra81adacbfdd6f166f9cf155340674ffd4179386b8b75068639547c11%40%3Ccommits.dolphinscheduler.apache.org%3E
Mailing List mailing-list
https://lists.apache.org/thread.html/r9fbe24539a873032b3e41243d44a730d6a2aae26335ac1e3271ea47d%40%3Ccommits.dolphinscheduler.apache.org%3E
Mailing List mailing-list
https://lists.apache.org/thread.html/r33452d7b99a293bcf8f3e4bd664943847e2602e03a9e45d09d3f508a%40%3Ccommits.dolphinscheduler.apache.org%3E
Mailing List mailing-list
https://lists.apache.org/thread.html/r0de5e3d5516467c9429a8d4356eca17ccf156337345ac6b104748acb%40%3Ccommits.dolphinscheduler.apache.org%3E
Mailing List, Vendor Advisory
https://lists.apache.org/thread.html/rcbe4c248ef0c566e99fd19388a6c92aeef88167286546b675e9b1769%40%3Cdev.dolphinscheduler.apache.org%3E
Mailing List mailing-list
http://www.openwall.com/lists/oss-security/2024/04/09/8
Scores
CVSS v3
9.8
EPSS
0.1135
EPSS Percentile
93.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (3)
apache/dolphinscheduler
1.2.0
apache/dolphinscheduler
1.2.1
org.apache.dolphinscheduler/dolphinscheduler
0 - 1.3.0Maven
Published
Dec 18, 2020
Tracked Since
Feb 18, 2026