PT-2025-35703 · Apache · Apache Dolphinscheduler

L0Ne1Y

·

Published

2025-09-03

·

Updated

2025-09-17

·

CVE-2024-43115

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions prior to 3.2.2
Description An authenticated user can execute any shell script on the server through the alert script functionality due to improper input validation.
Recommendations Upgrade to version 3.3.1.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-43115
GHSA-3VCP-R62V-XPVG

Affected Products

Apache Dolphinscheduler