Description
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.
Remediation
References
https://lists.apache.org/thread/r0wqzkjsoq17j6ww381kmpx3jjp9hb6r
http://www.openwall.com/lists/oss-security/2023/11/22/2
Related Vulnerabilities
CVE-2023-30846 Vulnerability in npm package typed-rest-client
CVE-2023-29216 Vulnerability in maven package org.apache.linkis:linkis-common
CVE-2023-48238 Vulnerability in npm package json-web-token
CVE-2020-11972 Vulnerability in maven package org.apache.camel:camel-rabbitmq
CVE-2017-5646 Vulnerability in maven package org.apache.knox:gateway