PT-2023-14788 · Apache · Apache Dolphinscheduler

·

CVE-2022-45875

·

Publicado

2023-01-04

·

Atualizado

2025-04-19

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions 3.0.1 and prior versions Apache DolphinScheduler versions 3.1.0 and prior versions
Description The issue is related to improper validation of script alert plugin parameters in Apache DolphinScheduler, which can lead to remote command execution. This can be performed only by authenticated users who can log in to the system. The attack poses a significant risk to data and infrastructure, allowing attackers to execute arbitrary code on systems remotely.
Recommendations For Apache DolphinScheduler versions 3.0.1 and prior, upgrade to version 3.0.2. For Apache DolphinScheduler versions 3.1.0 and prior, upgrade to version 3.1.1.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-45875
GHSA-3XH5-8HVQ-RC8X
PYSEC-2023-4

Produtos afetados

Apache Dolphinscheduler