Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.
2023-01-04T15:15:09.163
2025-04-03T16:15:28.510
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | dolphinscheduler | < 3.0.2 | Yes |
Application | apache | dolphinscheduler | 3.1.0 | Yes |