cbcvebase.
CVE-2022-45875
published 2023-01-04

CVE-2022-45875: Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache…

PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.55%
83.2th percentile
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachedolphinscheduler< 3.0.23.0.2
apachedolphinscheduler
apache_software_foundationapache_dolphinscheduler3.0 – 3.0.1
apache_software_foundationapache_dolphinscheduler3.1 – 3.1.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.