dolphinschedulerGHSA-vpgf-fgm8-gxr2
Apache DolphinScheduler vulnerable to Path Traversal
Medium6.5CVE-2022-26884 · Published Oct 28, 2022 · updated Nov 8, 2023
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler Maven | < 2.0.6 | 2.0.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2022-26884
More dolphinscheduler advisories
All dolphinscheduler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 202024 | Remote Code Execution in Apache Dolphinscheduler | Critical9.8 | 3.2.1 |
| Nov 242023 | Apache DolphinScheduler sensitive information disclosure | High7.5 | 3.0.2 |
| Jan 42023 | Apache DolphinScheduler vulnerable to Improper Input Validation | Critical9.8 | 3.0.2+1 more |
| Nov 12022 | Apache DolphinScheduler vulnerable to Path Traversal | Medium6.5 | 3.0.0 |
| Mar 312022 | Uncontrolled Resource Consumption in Apache DolphinScheduler | High7.5 | 2.0.5 |
| Feb 92022 | Remote code execution in DolphinScheduler | Critical9.8 | 1.3.0 |