PYSEC-2023-4

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/apache-dolphinscheduler/PYSEC-2023-4.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2023-4
Aliases
Published
2023-01-04T15:15:00Z
Modified
2023-11-08T04:10:54.065001Z
Summary
[none]
Details

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions.

References

Affected packages

PyPI / apache-dolphinscheduler

Package

Name
apache-dolphinscheduler
View open source insights on deps.dev
Purl
pkg:pypi/apache-dolphinscheduler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.2

Affected versions

0.*

0.1.0
0.1.1

2.*

2.0.5
2.0.5.1
2.0.7

3.*

3.0.0a0
3.0.0b1
3.0.0b2
3.0.0
3.0.1