Skip to content
dolphinschedulerGHSA-qg5x-66hp-cw5p

Uncontrolled Resource Consumption in Apache DolphinScheduler

High7.5CVE-2022-25598 · Published Mar 31, 2022 · updated Feb 16, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.dolphinscheduler:dolphinscheduler
Maven
< 2.0.52.0.5
Details and references

Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks. Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1333, CWE-400
Also known as
CVE-2022-25598, PYSEC-2022-176

More dolphinscheduler advisories

All
DateAdvisory
Feb 92022Remote code execution in DolphinScheduler
CVE-2020-11974Critical9.8fixed in 1.3.0
Oct 282022Apache DolphinScheduler vulnerable to Path Traversal
CVE-2022-26884Medium6.5fixed in 2.0.6
Nov 12022Apache DolphinScheduler vulnerable to Path Traversal
CVE-2022-34662Medium6.5fixed in 3.0.0
Jan 42023Apache DolphinScheduler vulnerable to Improper Input Validation
CVE-2022-45875Critical9.8fixed in 3.0.2, 3.1.1
Nov 242023Apache DolphinScheduler sensitive information disclosure
CVE-2023-48796High7.5fixed in 3.0.2
Feb 202024Remote Code Execution in Apache Dolphinscheduler
CVE-2023-49109Critical9.8fixed in 3.2.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.