Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.
| Software | From | Fixed in |
|---|---|---|
| apache / dolphinscheduler | - | 3.0.2 |
| apache / dolphinscheduler | 3.1.0 | 3.1.0.x |
org.apache.dolphinscheduler / dolphinscheduler
|
- | 3.0.2 |
org.apache.dolphinscheduler / dolphinscheduler
|
3.1.0 | 3.1.0.x |
org.apache.dolphinscheduler / dolphinscheduler
|
3.1.0 | 3.1.1 |