An authenticated Apache DolphinScheduler user can exploit it. The user must be able to create a resource with a filename containing shell command substitution syntax and provide its path to the Alert Script plugin's /test-send endpoint.
Successful exploitation allows arbitrary command execution with the privileges of the DolphinScheduler service process.
The available information does not state whether the Alert Script plugin or its /test-send endpoint is enabled or accessible in a default deployment. The issue affects DolphinScheduler versions before 3.4.3 when the described plugin workflow can be used.
Upgrade Apache DolphinScheduler to version 3.4.3, which fixes the issue. If an upgrade cannot be performed immediately, restrict authenticated users' ability to create resources with attacker-controlled filenames and access the Alert Script plugin's /test-send endpoint where possible.