PT-2023-14788 · Apache · Apache Dolphinscheduler

·

CVE-2022-45875

·

Published

2023-01-04

·

Updated

2025-04-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache DolphinScheduler versions 3.0.1 and prior versions Apache DolphinScheduler versions 3.1.0 and prior versions
Description The issue is related to improper validation of script alert plugin parameters in Apache DolphinScheduler, which can lead to remote command execution. This can be performed only by authenticated users who can log in to the system. The attack poses a significant risk to data and infrastructure, allowing attackers to execute arbitrary code on systems remotely.
Recommendations For Apache DolphinScheduler versions 3.0.1 and prior, upgrade to version 3.0.2. For Apache DolphinScheduler versions 3.1.0 and prior, upgrade to version 3.1.1.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45875
GHSA-3XH5-8HVQ-RC8X
PYSEC-2023-4

Affected Products

Apache Dolphinscheduler