oss-sec mailing list archives

CVE-2022-45462: Apache DolphinScheduler prior to 2.0.5 have command execution vulnerability


From: Jiajie Zhong <zhongjiajie () apache org>
Date: Wed, 23 Nov 2022 02:19:51 +0000

Severity: moderate

Description:

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in 
users. We recommend you upgrade to version 2.0.6 or higher

Credit:

This issue was discovered by Jigang Dong of M1QLin Security Team


Current thread: