CVE-2024-43115

HIGH8.8EPSS 0.10%

Apache DolphinScheduler vulnerable to Alert Script Attack

Published: 9/9/2025Modified: 11/5/2025
Also known as:GHSA-3vcp-r62v-xpvg

Description

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (4)