CRITICAL
Apache DolphinScheduler: Remote command execution Vulnerability in script alert plugin
Published Jan 4, 2023
9.3
CRITICALCVSS 4.0
EPSS 2.55%
Description
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.
Affected products
-
- Version 3.0StatusaffectedConstraints<=3.0.1
- Version 3.1StatusaffectedConstraints<=3.1.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache DolphinScheduler | unaffected |
|
OR
- < 3.0.2
- 3.1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://www.openwall.com/lists/oss-security/2023/11/22/2
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0036 Advisory
- https://github.com/advisories/GHSA-3xh5-8hvq-rc8x Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-dolphinscheduler/PYSEC-2023-4.yaml
- https://lists.apache.org/thread/r0wqzkjsoq17j6ww381kmpx3jjp9hb6r vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-45875
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 4, 2023
Updated Apr 3, 2025
Reserved Nov 24, 2022
Link CVE-2022-45875
CISA Vulnrichment
Updated Apr 3, 2025
ENISA EUVD
EUVD-2023-0036 GHSA-3XH5-8HVQ-RC8X Assigner apache
Published Jan 4, 2023
Updated Apr 3, 2025
Exploited since n/a
Link EUVD-2023-0036