CVE-2024-43166
BaseFortify
Publication date: 2025-09-03
Last updated on: 2025-11-04
Assigner: Apache Software Foundation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | dolphinscheduler | to 3.2.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Incorrect Default Permissions issue in Apache DolphinScheduler versions before 3.2.2. It means that the software may have default settings that grant more permissions than intended, potentially allowing unauthorized access or actions.
How can this vulnerability impact me? :
The impact of this vulnerability could include unauthorized users gaining access to sensitive functions or data within Apache DolphinScheduler due to overly permissive default settings, which may lead to security breaches or misuse of the system.
What immediate steps should I take to mitigate this vulnerability?
Users are recommended to upgrade Apache DolphinScheduler to version 3.3.1 or later, as this version fixes the Incorrect Default Permissions vulnerability.