Skip to content
dolphinschedulerGHSA-rrpj-r8h7-rm7r

Apache DolphinScheduler Incorrect Default Permissions Vulnerability

LowCVE-2024-43166 · Published Sep 3, 2025

Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.dolphinscheduler:dolphinscheduler
Maven
< 3.3.13.3.1
Details and references

More dolphinscheduler advisories

All dolphinscheduler

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.