AI analysis
Apache DolphinScheduler versions before 3.4.3 contain an OS command injection flaw (CWE-78) in the Alert Script plugin: the scriptPath parameter is passed into a /bin/sh -c command without adequate neutralization of shell metacharacters. An authenticated attacker can trigger it by creating a resource whose filename contains shell command substitution syntax, such as $(...), and then supplying that path to the Alert Script plugin's /test-send endpoint, causing the injected command to execute when the alert script runs. Successful exploitation yields arbitrary command execution with the privileges of the DolphinScheduler service process. All deployments of Apache DolphinScheduler before 3.4.3 are affected, and users are advised to upgrade to 3.4.3. There is no known public proof of concept and no evidence of in-the-wild exploitation at this time.
What to do: Upgrade to Apache DolphinScheduler 3.4.3, which fixes the issue. If immediate upgrade is not possible, restrict access to the Alert Script plugin's /test-send endpoint and to resource creation/upload to trusted, least-privileged users, and run the DolphinScheduler service under a minimally privileged account. Review logs for resources with shell metacharacters such as $(...) in filenames and for unexpected commands spawned by the alert script process.
Affected
| Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
moderateLikely thousands of self-hosted deployments worldwide (order of magnitude 10^3–10^4), with only a subset internet-exposed — DolphinScheduler is open-source, self-hosted workflow orchestration software typically deployed within enterprise environments, so the install base is far smaller than mass-market products and many instances sit on internal networks;…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.