diff --git a/advisories/github-reviewed/2024/08/GHSA-2fm6-mv57-p2qh/GHSA-2fm6-mv57-p2qh.json b/advisories/github-reviewed/2024/08/GHSA-2fm6-mv57-p2qh/GHSA-2fm6-mv57-p2qh.json index 0df26cb8a0a74..7bb1474e5001d 100644 --- a/advisories/github-reviewed/2024/08/GHSA-2fm6-mv57-p2qh/GHSA-2fm6-mv57-p2qh.json +++ b/advisories/github-reviewed/2024/08/GHSA-2fm6-mv57-p2qh/GHSA-2fm6-mv57-p2qh.json @@ -9,10 +9,6 @@ "summary": "Apache Dolphinscheduler Code Injection vulnerability", "details": "Exposure of Remote Code Execution in Apache Dolphinscheduler.\n\nThis issue affects Apache DolphinScheduler: before 3.2.2. \n\nWe recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.", "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" - }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" @@ -29,7 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "3.1.0" }, { "fixed": "3.2.2"