Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/r0wqzkjsoq17j6ww381kmpx3jjp9hb6r | Mailing List Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-01-04 07:15
Updated : 2023-01-10 10:33
NVD link : CVE-2022-45875
Mitre link : CVE-2022-45875
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
apache
- dolphinscheduler