[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2022-45875: Apache DolphinScheduler: Remote command execution Vulnerability in sc
From:       Wenjun Ruan <wenjun () apache ! org>
Date:       2023-11-22 4:31:28
Message-ID: 375127d6-abc0-16b3-af1f-858e248d9657 () apache ! org
[Download RAW message or body]

Severity: low

Affected versions:

- Apache DolphinScheduler 3.0 through 3.0.1
- Apache DolphinScheduler 3.1 through 3.1.0

Description:

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid \
remote command execution vulnerability.  This issue affects Apache DolphinScheduler version \
3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only \
by authenticated users which can login to DS.

Credit:

4ra1n of Chaitin Tech (finder)

References:

https://lists.apache.org/thread/r0wqzkjsoq17j6ww381kmpx3jjp9hb6r
https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2022-45875


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic