dolphinschedulerGHSA-rrpj-r8h7-rm7r
Apache DolphinScheduler Incorrect Default Permissions Vulnerability
LowCVE-2024-43166 · Published Sep 3, 2025
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | < 3.3.1 | 3.3.1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-276
- Also known as
- CVE-2024-43166
More dolphinscheduler advisories
All dolphinscheduler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 24 | Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability | Medium6.3 | 3.3.1 |
| Apr 24 | Apache DolphinScheduler has an Incorrect Authorization Vulnerability | High8.1 | 3.4.1 |
| Apr 9 | Apache DolphinScheduler vulnerable to sensitive information disclosure | High7.5 | 3.2.0 |
| Sep 92025 | Apache DolphinScheduler vulnerable to Alert Script Attack | High8.8 | 3.2.2 |
| Aug 122024 | Apache DolphinScheduler: Resource File Read And Write Vulnerability | High8.1 | 3.2.2 |
| Aug 122024 | Apache DolphinScheduler: RCE by arbitrary js execution | High8.8 | 3.2.2 |