dolphinschedulerGHSA-fp35-xrrr-3gph
Apache DolphinScheduler vulnerable to Path Traversal
Medium6.5CVE-2022-34662 · Published Nov 1, 2022 · updated May 6, 2025
When users add resources to the resource center with a relation path, this vulnerability will cause path traversal issues for logged-in users. Users should upgrade to version 3.0.0 to avoid this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | < 3.0.0 | 3.0.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2022-34662
More dolphinscheduler advisories
All dolphinscheduler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 202024 | Remote Code Execution in Apache Dolphinscheduler | Critical9.8 | 3.2.1 |
| Nov 242023 | Apache DolphinScheduler sensitive information disclosure | High7.5 | 3.0.2 |
| Jan 42023 | Apache DolphinScheduler vulnerable to Improper Input Validation | Critical9.8 | 3.0.2+1 more |
| Oct 282022 | Apache DolphinScheduler vulnerable to Path Traversal | Medium6.5 | 2.0.6 |
| Mar 312022 | Uncontrolled Resource Consumption in Apache DolphinScheduler | High7.5 | 2.0.5 |
| Feb 92022 | Remote code execution in DolphinScheduler | Critical9.8 | 1.3.0 |