VYPR
Critical severityNVD Advisory· Published Nov 23, 2022· Updated Apr 25, 2025

Apache DolphinScheduler prior to 2.0.5 have command execution vulnerability

CVE-2022-45462

Description

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.dolphinscheduler:dolphinscheduler-alert-pluginsMaven
< 2.0.62.0.6

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.

CVE-2022-45462 · critical · VYPR