dolphinschedulerGHSA-3xh5-8hvq-rc8x
Apache DolphinScheduler vulnerable to Improper Input Validation
Critical9.8CVE-2022-45875 · Published Jan 4, 2023 · updated Feb 13, 2025
Apache DolphinScheduler improperly validates script alert plugin parameters and is vulnerable to remote command execution. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. Users should upgrade to version 3.0.2 or 3.1.1.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | < 3.0.2 | 3.0.2 |
| >= 3.1.0, < 3.1.1 | 3.1.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- CVE-2022-45875, PYSEC-2023-4
More dolphinscheduler advisories
All dolphinscheduler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 202024 | Remote Code Execution in Apache Dolphinscheduler | Critical9.8 | 3.2.1 |
| Nov 242023 | Apache DolphinScheduler sensitive information disclosure | High7.5 | 3.0.2 |
| Nov 12022 | Apache DolphinScheduler vulnerable to Path Traversal | Medium6.5 | 3.0.0 |
| Oct 282022 | Apache DolphinScheduler vulnerable to Path Traversal | Medium6.5 | 2.0.6 |
| Mar 312022 | Uncontrolled Resource Consumption in Apache DolphinScheduler | High7.5 | 2.0.5 |
| Feb 92022 | Remote code execution in DolphinScheduler | Critical9.8 | 1.3.0 |