===================================================================== CERT-Renater Note d'Information No. 2023/VULN494 _____________________________________________________________________ DATE : 29/11/2023 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Apache DolphinScheduler versions 3.0.1 and prior versions. ===================================================================== https://lists.apache.org/thread/m883zmgloz7wtwwn9bt6n7cdwqnf97x9 _____________________________________________________________________ CVE-2022-45875: Apache DolphinScheduler: Remote command execution Vulnerability in script alert plugin Severity: low Affected versions: - Apache DolphinScheduler 3.0 through 3.0.1 - Apache DolphinScheduler 3.1 through 3.1.0 Description: Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS. Credit: 4ra1n of Chaitin Tech (finder) References: https://lists.apache.org/thread/r0wqzkjsoq17j6ww381kmpx3jjp9hb6r https://dolphinscheduler.apache.org https://www.cve.org/CVERecord?id=CVE-2022-45875 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================