apache Vulnerabilities and Affected Products
Vulnerabilities associated with dolphinscheduler.
Products
Clear product- HTTP Server21 vulnerabilities
- OFBiz21 vulnerabilities
- Struts18 vulnerabilities
- inlong17 vulnerabilities
- Tomcat16 vulnerabilities
- airflow15 vulnerabilities
- Solr10 vulnerabilities
- traffic_server8 vulnerabilities
- ActiveMQ7 vulnerabilities
- linkis7 vulnerabilities
- cloudstack6 vulnerabilities
- cxf6 vulnerabilities
- dolphinscheduler6 vulnerabilities
- hertzbeat6 vulnerabilities
- http_server6 vulnerabilities
- pulsar6 vulnerabilities
- streampark6 vulnerabilities
- zeppelin6 vulnerabilities
- Apache HTTP Server5 vulnerabilities
- Apache Tomcat5 vulnerabilities
- kafka5 vulnerabilities
- ambari4 vulnerabilities
- Apache OFBiz4 vulnerabilities
- Apache Tika4 vulnerabilities
- camel4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Apache DolphinScheduler: Resource File Read And Write VulnerabilityFile read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue. | CVSS-v4.0 | EPSS5.99% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX | |
Apache DolphinScheduler: Arbitrary js execution as root for authenticated usersImproper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it. This issue affects Apache DolphinScheduler: until 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue. CWE-20Feb 23, 2024 | CVSS-v4.0 | EPSS1.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-50270MEDIUM | Apache DolphinScheduler: Session do not expire after password changeSession Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue. | CVSS6.5v3.1 | EPSS1.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49250HIGH | Apache DolphinScheduler: Insecure TLS TrustManager used in HttpUtilBecause the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache DolphinScheduler: before 3.2.0. Users are recommended to upgrade to version 3.2.1, which fixes the issue. CWE-295Feb 20, 2024 | CVSS7.3v3.1 | EPSS0.704% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49109CRITICAL | Remote Code Execution in Apache DolphinschedulerExposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue. CWE-94Feb 20, 2024 | CVSS9.8v3.1 | EPSS2.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Apache DolphinScheduler: Arbitrary js execute as root for authenticated usersImproper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9. Users are recommended to upgrade to version 3.1.9, which fixes the issue. CWE-20Dec 30, 2023 | CVSS-v4.0 | EPSS1.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |