dolphinschedulerGHSA-qg5x-66hp-cw5p
Uncontrolled Resource Consumption in Apache DolphinScheduler
High7.5CVE-2022-25598 · Published Mar 31, 2022 · updated Feb 16, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | < 2.0.5 | 2.0.5 |
Details and references
Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks. Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.
More dolphinscheduler advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 92022 | Remote code execution in DolphinScheduler CVE-2020-11974Critical9.8fixed in 1.3.0 | Critical9.8 | 1.3.0 |
| Oct 282022 | Apache DolphinScheduler vulnerable to Path Traversal CVE-2022-26884Medium6.5fixed in 2.0.6 | Medium6.5 | 2.0.6 |
| Nov 12022 | Apache DolphinScheduler vulnerable to Path Traversal CVE-2022-34662Medium6.5fixed in 3.0.0 | Medium6.5 | 3.0.0 |
| Jan 42023 | Apache DolphinScheduler vulnerable to Improper Input Validation CVE-2022-45875Critical9.8fixed in 3.0.2, 3.1.1 | Critical9.8 | 3.0.2, 3.1.1 |
| Nov 242023 | Apache DolphinScheduler sensitive information disclosure CVE-2023-48796High7.5fixed in 3.0.2 | High7.5 | 3.0.2 |
| Feb 202024 | Remote Code Execution in Apache Dolphinscheduler CVE-2023-49109Critical9.8fixed in 3.2.1 | Critical9.8 | 3.2.1 |