← Back to browse · API

CVE-2022-45875

Severity
CRITICAL
CVSS
9.8
EPSS
0.0255
Risk score
40.09
CISA KEV
No
PoC
No
Published
2023-01-04
Modified
2025-04-03
First seen
2026-08-07
Aliases
EUVD-2023-0036, GHSA-3XH5-8HVQ-RC8X, PYSEC-2023-4
Products
Apache Software Foundation:Apache DolphinScheduler 3.0 ≤3.0.1, Apache Software Foundation:Apache DolphinScheduler 3.1 ≤3.1.0
Sources
euvd EUVD-2023-0036

Description

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.

References