Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-45462
- https://lists.apache.org/thread/2f126y32bf1v3mvxkdgt2jr5j3l1t01w
- https://github.com/apache/dolphinscheduler/pull/10744
- https://github.com/apache/dolphinscheduler/pull/9834
- http://www.openwall.com/lists/oss-security/2022/11/23/1
- https://github.com/advisories/GHSA-wqg7-mx6p-2rw3