Back

CRITICAL

Apache DolphinScheduler: Remote command execution Vulnerability in script alert plugin

Published Jan 4, 2023

Description

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 4, 2023
Updated Apr 3, 2025
Reserved Nov 24, 2022
CISA Vulnrichment
Updated Apr 3, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Jan 4, 2023
Updated Apr 3, 2025
Exploited since n/a
EUVD-2023-0036 GHSA-3XH5-8HVQ-RC8X