CVE-2022-45875 is a critical remote command execution vulnerability affecting Apache DolphinScheduler versions 3.0.1 and prior, and 3.1.0 and prior. It stems from improper validation of script alert plugin parameters, allowing authenticated users to execute arbitrary commands. With a CVSS score of 9.8, this vulnerability presents a severe risk of complete compromise (confidentiality, integrity, and availability). Despite its high severity, there is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.2CPE matchmatch criteria | cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:apache:dolphinscheduler:3.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.