Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
The vulnerability classified as CWE-94 (Improper Control of Generation of Code) allows an attacker to remotely inject and execute arbitrary code on the server. The attack can be performed over the network without the need to possess an account or user interaction. The detailed exploitation mechanism was not disclosed in the vendor's description.
An attacker can gain full control over the vulnerable server, including access to sensitive data, modification of configuration, and potentially lateral movement within the internal network.
Apache DolphinScheduler should be updated immediately to version 3.2.2, which eliminates the described vulnerability. Detailed information is available in the vendor's references.
Apache DolphinScheduler in all versions before 3.2.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Dolphinscheduler
APPApache3.0.0 – 3.2.2 (excl.)
Related vulnerabilities
Nieprawidłowe domyślne uprawnienia w Apache DolphinScheduler
RCE w Apache DolphinScheduler — zdalne wykonanie kodu bez uwierzytelnienia
Apache DolphinScheduler — RCE przez brak walidacji parametrów wtyczki alert
Command injection w Apache DolphinScheduler — zarządzanie alertami
RCE w Apache DolphinScheduler przez MySQL Connector/J