In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
{
"github_reviewed": true,
"severity": "HIGH",
"github_reviewed_at": "2021-11-02T18:48:35Z",
"nvd_published_at": "2021-11-01T10:15:00Z",
"cwe_ids": [
"CWE-89"
]
}