Apache
Apache Dolphinscheduler: vulnerabilidades y CVE
Apache Dolphinscheduler tiene 41 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE41
Últimos 12 meses17
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81569 | Media (4.3) | 0.23% | — | 29 sept 2026 | An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that… |
| CVE-2026-78214 | Media (5.3) | 0.35% | — | 29 sept 2026 | An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator… |
| CVE-2026-71899 | Media (6.5) | 0.23% | — | 29 sept 2026 | A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows… |
| CVE-2026-71898 | Media (4.3) | 0.18% | — | 29 sept 2026 | An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT… |
| CVE-2026-71897 | Media (4.3) | 0.18% | — | 29 sept 2026 | An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions.… |
| CVE-2026-82804 | Alta (8.8) | 0.50% | — | 29 sept 2026 | The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this… |
| CVE-2026-66083 | Media (6.5) | 0.23% | — | 29 sept 2026 | The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access.… |
| CVE-2026-57590 | Alta (8.1) | 0.23% | — | 24 sept 2026 | A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated… |
| CVE-2026-49050 | Alta (8.8) | 0.58% | — | 25 ago 2026 | General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. |
| CVE-2026-47340 | Media (6.5) | 0.55% | — | 17 jun 2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are… |
| CVE-2026-42357 | Media (6.5) | 0.49% | — | 17 jun 2026 | Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2.… |
| CVE-2026-41280 | Media (4.9) | 0.54% | — | 17 jun 2026 | Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are… |
| CVE-2026-32967 | Crítica (9.1) | 0.55% | — | 17 jun 2026 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes… |
| CVE-2026-32966 | Crítica (9.8) | 0.66% | — | 17 jun 2026 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to… |
| CVE-2026-23902 | Alta (8.1) | 0.45% | — | 24 abr 2026 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects… |
| CVE-2025-62233 | Media (6.3) | 0.54% | — | 24 abr 2026 | Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can… |
| CVE-2025-62188 | Alta (7.5) | 0.52% | — | 9 abr 2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database… |
| CVE-2024-43166 | Crítica (9.8) | 0.52% | — | 3 sept 2025 | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue. |
| CVE-2024-43115 | Alta (8.8) | 0.51% | — | 3 sept 2025 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are… |
| CVE-2024-43202 | Crítica (9.8) | 2.1% | — | 20 ago 2024 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue. |
| CVE-2024-30188 | Alta (8.1) | 6.0% | — | 12 ago 2024 | File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are… |
| CVE-2024-29831 | Alta (8.8) | 1.2% | — | 12 ago 2024 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade… |
| CVE-2024-23320 | Alta (8.8) | 1.4% | — | 23 feb 2024 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix… |
| CVE-2023-51770 | Alta (7.5) | 1.2% | — | 20 feb 2024 | Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue. |
| CVE-2023-50270 | Media (6.5) | 1.3% | — | 20 feb 2024 | Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue. |
| CVE-2023-49250 | Alta (7.3) | 0.70% | — | 20 feb 2024 | Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache… |
| CVE-2023-49109 | Crítica (9.8) | 2.3% | — | 20 feb 2024 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue. |
| CVE-2023-49299 | Alta (8.8) | 1.4% | — | 30 dic 2023 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.… |
| CVE-2023-49620 | Media (6.5) | 1.1% | — | 30 nov 2023 | Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0… |
| CVE-2023-49068 | Alta (7.5) | 1.1% | — | 27 nov 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1. Users are recommended to upgrade to version 3.2.1, which… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.