PT-2026-102608 · Apache · Dolphinscheduler
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache DolphinScheduler versions prior to 3.4.3
Description
An authenticated user can achieve arbitrary command execution with the privileges of the DolphinScheduler service process. This occurs because the
scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, enabling shell command substitution. An attacker can exploit this by creating a resource with a filename containing shell command substitution syntax, such as $(...), and providing that path to the Alert Script plugin's /test-send endpoint.Recommendations
Upgrade to version 3.4.3.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dolphinscheduler