HomeDefault status
unaffected
Any version before 3.2.2
affected
Description
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
Problem types
CWE-20 Improper Input Validation
Product status
Any version before 3.2.2
Credits
L0ne1y
References
www.openwall.com/lists/oss-security/2025/09/03/1
lists.apache.org/thread/qm36nrsv1vrr2j4o5q2wo75h3686hrnj