PT-2023-14788 · Apache · Apache Dolphinscheduler

4Ra1N

·

Published

2023-01-04

·

Updated

2025-04-19

·

CVE-2022-45875

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions 3.0.1 and prior versions Apache DolphinScheduler versions 3.1.0 and prior versions
Description The issue is related to improper validation of script alert plugin parameters in Apache DolphinScheduler, which can lead to remote command execution. This can be performed only by authenticated users who can log in to the system. The attack poses a significant risk to data and infrastructure, allowing attackers to execute arbitrary code on systems remotely.
Recommendations For Apache DolphinScheduler versions 3.0.1 and prior, upgrade to version 3.0.2. For Apache DolphinScheduler versions 3.1.0 and prior, upgrade to version 3.1.1.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-45875
GHSA-3XH5-8HVQ-RC8X
PYSEC-2023-4

Affected Products

Apache Dolphinscheduler