In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler-server(Maven) | 0 | 1.3.6 | N/A |
CVSS Metrics