This issue affects Apache DolphinScheduler: before 3.2.2.
Users are recommended to upgrade to version 3.3.1, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54957 | Apache DolphinScheduler Incorrect Default Permissions Vulnerability |
Github GHSA |
GHSA-rrpj-r8h7-rm7r | Apache DolphinScheduler Incorrect Default Permissions Vulnerability |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Sep 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* |
Wed, 03 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache dolphinscheduler |
|
| Vendors & Products |
Apache
Apache dolphinscheduler |
Wed, 03 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 03 Sep 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue. | |
| Weaknesses | CWE-276 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:08:48.628Z
Reserved: 2024-08-07T10:39:22.903Z
Link: CVE-2024-43166
Updated: 2025-11-04T21:08:48.628Z
Status : Modified
Published: 2025-09-03T10:15:36.463
Modified: 2025-11-04T22:16:03.300
Link: CVE-2024-43166
No data.
OpenCVE Enrichment
Updated: 2025-09-03T19:30:18Z
EUVD
Github GHSA