VDB
Sign up
—

PYSEC-2023-4

Quick fix

PYSEC-2023-4 — apache-dolphinscheduler: upgrade to the fixed version with the command below.

pip install --upgrade 'apache-dolphinscheduler>=3.0.2'

Details

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/apache-dolphinscheduler
Introduced in: 0Fixed in: 3.0.2
Fixpip install --upgrade 'apache-dolphinscheduler>=3.0.2'

References