VYPR

Dolphinscheduler

by Apache

Source repositories

CVEs (32)

  • CVE-2022-26885HigNov 24, 2022
    risk 0.42cvss 7.5epss 0.01

    When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.

  • CVE-2022-34662MedNov 1, 2022
    risk 0.42cvss 6.5epss 0.01

    When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher

  • CVE-2023-49250HigFeb 20, 2024
    risk 0.41cvss 7.3epss 0.01

    Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache DolphinScheduler: before 3.2.0. Users are recommended to upgrade to…

  • CVE-2026-47340MedJun 17, 2026
    risk 0.35cvss 6.5epss 0.00

    Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the…

  • CVE-2026-42357MedJun 17, 2026
    risk 0.35cvss 6.5epss 0.00

    Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which…

  • CVE-2023-50270MedFeb 20, 2024
    risk 0.35cvss 6.5epss 0.01

    Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

  • CVE-2023-49620MedNov 30, 2023
    risk 0.35cvss 6.5epss 0.01

    Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level…

  • CVE-2022-26884MedOct 28, 2022
    risk 0.35cvss 6.5epss 0.02

    Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.

  • CVE-2020-13922MedJan 11, 2021
    risk 0.35cvss 6.5epss 0.02

    Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

  • CVE-2025-62233MedApr 24, 2026
    risk 0.34cvss 6.3epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest,…

  • CVE-2026-41280MedJun 17, 2026
    risk 0.25cvss 4.9epss 0.00

    Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

  • CVE-2023-25601MedApr 20, 2023
    risk 0.21cvss 4.3epss 0.01

    On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version 3.0.0 to 3.1.1, you…

Page 2 of 2