PT-2025-35707 · Apache · Apache Dolphinscheduler

L0Ne1Y

·

Published

2025-09-03

·

Updated

2025-09-17

·

CVE-2024-43166

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions prior to 3.2.2
Description An incorrect default permissions issue exists in Apache DolphinScheduler.
Recommendations Upgrade to version 3.3.1.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-43166
GHSA-RRPJ-R8H7-RM7R

Affected Products

Apache Dolphinscheduler