CVE-2022-34662
Published on: Not Yet Published
Last Modified on: 11/02/2022 06:37:00 PM UTC
Certain versions of Dolphinscheduler from Apache contain the following vulnerability:
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher
- CVE-2022-34662 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Apache Software Foundation - Apache DolphinScheduler version <= 3.0.0-beta-1
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
No Description Provided | lists.apache.org text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apache | Dolphinscheduler | All | All | All | All |
- cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*:
Discovery Credit
This issue was discovered by Jigang Dong of M1QLin Security Team
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-34662 | 2022-11-01 16:39:07 |