CRITICAL🇵🇱 Wersja polska

CVE-2024-43202

CVSS 9.8v3.1pub. 2024-08-20upd. 2025-03-18

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-94 (Improper Control of Generation of Code) allows an attacker to remotely inject and execute arbitrary code on the server. The attack can be performed over the network without the need to possess an account or user interaction. The detailed exploitation mechanism was not disclosed in the vendor's description.

Impact

An attacker can gain full control over the vulnerable server, including access to sensitive data, modification of configuration, and potentially lateral movement within the internal network.

Mitigation & patch

Apache DolphinScheduler should be updated immediately to version 3.2.2, which eliminates the described vulnerability. Detailed information is available in the vendor's references.

Who is affected

Apache DolphinScheduler in all versions before 3.2.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Dolphinscheduler

    APP
    Apache
    3.0.0 – 3.2.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-43166CRITICAL9.8PL ✓same product

Nieprawidłowe domyślne uprawnienia w Apache DolphinScheduler

CVE-2023-49109CRITICAL9.8PL ✓same product

RCE w Apache DolphinScheduler — zdalne wykonanie kodu bez uwierzytelnienia

CVE-2022-45875CRITICAL9.8PL ✓same product

Apache DolphinScheduler — RCE przez brak walidacji parametrów wtyczki alert

CVE-2022-45462CRITICAL9.8PL ✓same product

Command injection w Apache DolphinScheduler — zarządzanie alertami

CVE-2020-11974CRITICAL9.8PL ✓same product

RCE w Apache DolphinScheduler przez MySQL Connector/J