Known Vulnerabilities for Dolphinscheduler by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Dolphinscheduler" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-62188 json | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerab... | Not Provided | 2026-04-09 | 2026-04-09 |
| CVE-2023-49620 json | 6.5 - MEDIUM | 2023-11-30 | 2023-12-05 | |
| CVE-2023-49299 json | 8.8 - HIGH | 2023-12-30 | 2024-01-05 | |
| CVE-2023-49068 json | 7.5 - HIGH | 2023-11-27 | 2023-12-01 | |
| CVE-2023-48796 json | 7.5 - HIGH | 2023-11-24 | 2023-12-01 | |
| CVE-2023-25601 json | On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker c... | 4.3 - MEDIUM | 2023-04-20 | 2023-05-01 |
| CVE-2022-45875 json | Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerabil... | 9.8 - CRITICAL | 2023-01-04 | 2023-11-22 |
| CVE-2022-45462 json | Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. ... | 9.8 - CRITICAL | 2022-11-23 | 2023-03-07 |
| CVE-2022-34662 json | When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in ... | 6.5 - MEDIUM | 2022-11-01 | 2023-11-07 |
| CVE-2022-26885 json | When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2... | 7.5 - HIGH | 2022-11-24 | 2023-08-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Dolphinscheduler | 1.3.4 | |||
| Application | Apache | Dolphinscheduler | 1.3.3 | |||
| Application | Apache | Dolphinscheduler | 1.3.2 | |||
| Application | Apache | Dolphinscheduler | 1.3.1 | |||
| Application | Apache | Dolphinscheduler | 1.3.0 | |||
| Application | Apache | Dolphinscheduler | 1.2.1 | |||
| Application | Apache | Dolphinscheduler | 1.2.0 | |||
| Application | Apache | Dolphinscheduler | 1.1.0 | |||
| Application | Apache | Dolphinscheduler | 1.0.5 | |||
| Application | Apache | Dolphinscheduler | 1.0.4 | |||
| Application | Apache | Dolphinscheduler | 1.0.3 | |||
| Application | Apache | Dolphinscheduler | 1.0.2 | |||
| Application | Apache | Dolphinscheduler | 1.0.1 | |||
| Application | Apache | Dolphinscheduler | 1.0.0 |