Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by authenticated users which can login to DS.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "3.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.1.0"
}
]
}