Skip to content

Apache DolphinScheduler Incorrect Default Permissions Vulnerability

Low severity GitHub Reviewed Published Sep 3, 2025 to the GitHub Advisory Database • Updated Sep 3, 2025

Package

maven org.apache.dolphinscheduler:dolphinscheduler (Maven)

Affected versions

< 3.3.1

Patched versions

3.3.1

Description

Incorrect Default Permissions vulnerability in Apache DolphinScheduler.

This issue affects Apache DolphinScheduler: before 3.2.2.

Users are recommended to upgrade to version 3.3.1, which fixes the issue.

References

Published by the National Vulnerability Database Sep 3, 2025
Published to the GitHub Advisory Database Sep 3, 2025
Reviewed Sep 3, 2025
Last updated Sep 3, 2025

Severity

Low

EPSS score

Exploit Prediction Scoring System (EPSS)

This score estimates the probability of this vulnerability being exploited within the next 30 days. Data provided by FIRST.
(17th percentile)

Weaknesses

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files. Learn more on MITRE.

CVE ID

CVE-2024-43166

GHSA ID

GHSA-rrpj-r8h7-rm7r
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.