CVE-2022-45462: Apache DolphinScheduler prior to 2.0.5 have command execution vulnerability
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache DolphinSchedulerto a version that resolves this vulnerability.Fixed in 2.0.6
Event History
Frequently Asked Questions
What is CVE-2022-45462?
CVE-2022-45462 is a vulnerability in the Alarm instance management of Apache DolphinScheduler that allows command injection when a specific command is configured.
Who is affected by CVE-2022-45462?
CVE-2022-45462 affects users of Apache DolphinScheduler versions up to and including 2.0.6.
How severe is CVE-2022-45462?
The severity of CVE-2022-45462 is rated as critical with a CVSS score of 9.8.
How can I fix CVE-2022-45462?
To fix CVE-2022-45462, it is recommended to upgrade to version 2.0.6 or higher of Apache DolphinScheduler.
Where can I find more information about CVE-2022-45462?
You can find more information about CVE-2022-45462 at the following references: [http://www.openwall.com/lists/oss-security/2022/11/23/1](http://www.openwall.com/lists/oss-security/2022/11/23/1), [https://lists.apache.org/thread/2f126y32bf1v3mvxkdgt2jr5j3l1t01w](https://lists.apache.org/thread/2f126y32bf1v3mvxkdgt2jr5j3l1t01w)