CVE-2024-30188 is a high-severity file read and write vulnerability in Apache DolphinScheduler versions 3.1.0 through 3.2.1, allowing authenticated users to illegally access and manipulate resource files. With a CVSS score of 8.1 (High), this flaw is easily exploitable over the network with low complexity and user privileges, potentially leading to significant confidentiality and integrity impacts. While there is no evidence of active exploitation or public Metasploit/ExploitDB modules, Nuclei templates exist, and its high EPSS score indicates a significant probability of future exploitation. Users are strongly advised to upgrade to version 3.2.2 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.0, < 3.2.2CPE matchmatch criteria | cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.