Severity: low

Affected versions:

- Apache DolphinScheduler 3.0 through 3.0.1
- Apache DolphinScheduler 3.1 through 3.1.0

Description:

Improper validation of script alert plugin parameters in Apache 
DolphinScheduler to avoid remote command execution vulnerability.  This issue 
affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 
and prior versions.
This attack can be performed only by authenticated users which can login to DS.

Credit:

4ra1n of Chaitin Tech (finder)

References:

https://lists.apache.org/thread/r0wqzkjsoq17j6ww381kmpx3jjp9hb6r
https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2022-45875

Reply via email to