First published: Wed Nov 23 2022(Updated: )
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache DolphinScheduler | <2.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45462 is a vulnerability in the Alarm instance management of Apache DolphinScheduler that allows command injection when a specific command is configured.
CVE-2022-45462 affects users of Apache DolphinScheduler versions up to and including 2.0.6.
The severity of CVE-2022-45462 is rated as critical with a CVSS score of 9.8.
To fix CVE-2022-45462, it is recommended to upgrade to version 2.0.6 or higher of Apache DolphinScheduler.
You can find more information about CVE-2022-45462 at the following references: [http://www.openwall.com/lists/oss-security/2022/11/23/1](http://www.openwall.com/lists/oss-security/2022/11/23/1), [https://lists.apache.org/thread/2f126y32bf1v3mvxkdgt2jr5j3l1t01w](https://lists.apache.org/thread/2f126y32bf1v3mvxkdgt2jr5j3l1t01w)