Apache DolphinScheduler
cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*
- >= 3.2.0, < 3.3.1
A deserialization vulnerability allowing the injection of malicious class types has been identified in the RPC module of Apache DolphinScheduler. This issue affects versions 3.2.0 prior to 3.3.1. Attackers with access to Master or Worker nodes can exploit this vulnerability by creating a StandardRpcRequest, injecting a harmful class type, and sending the modified RPC requests to the affected nodes.
Exploitation of this vulnerability could lead to remote code execution on the Master or Worker nodes.
Users are advised to upgrade to Apache DolphinScheduler version 3.3.1, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.