dolphinschedulerGHSA-3vcp-r62v-xpvg
Apache DolphinScheduler vulnerable to Alert Script Attack
High8.8CVE-2024-43115 · Published Sep 9, 2025 · updated Nov 5, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | < 3.2.2 | 3.2.2 |
Details and references
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- CVE-2024-43115
More dolphinscheduler advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 32025 | Apache DolphinScheduler Incorrect Default Permissions Vulnerability CVE-2024-43166Lowfixed in 3.3.1 | Low | 3.3.1 |
| Apr 9 | Apache DolphinScheduler vulnerable to sensitive information disclosure CVE-2025-62188High7.5fixed in 3.2.0 | High7.5 | 3.2.0 |
| Apr 24 | Apache DolphinScheduler has an Incorrect Authorization Vulnerability CVE-2026-23902High8.1fixed in 3.4.1 | High8.1 | 3.4.1 |
| Apr 24 | Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability CVE-2025-62233Medium6.3fixed in 3.3.1 | Medium6.3 | 3.3.1 |
| Aug 122024 | Apache DolphinScheduler: Resource File Read And Write Vulnerability CVE-2024-30188High8.1fixed in 3.2.2 | High8.1 | 3.2.2 |
| Aug 122024 | Apache DolphinScheduler: RCE by arbitrary js execution CVE-2024-29831High8.8fixed in 3.2.2 | High8.8 | 3.2.2 |