Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vcp-r62v-xpvg

Опубликовано: 09 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Apache DolphinScheduler vulnerable to Alert Script Attack

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script.

This issue affects Apache DolphinScheduler: before 3.2.2.

Users are recommended to upgrade to version 3.3.1, which fixes the issue.

Пакеты

Наименование

org.apache.dolphinscheduler:dolphinscheduler

maven
Затронутые версииВерсия исправления

< 3.2.2

3.2.2

EPSS

Процентиль: 40%
0.00494
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
nvd
12 месяцев назад

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.

EPSS

Процентиль: 40%
0.00494
Низкий

8.8 High

CVSS3

Дефекты

CWE-20