« Volver al listado

Apache

Apache Dolphinscheduler: vulnerabilidades y CVE

Apache Dolphinscheduler tiene 41 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE41
Últimos 12 meses17
Críticas8
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81569Media (4.3)0.23%—29 sept 2026
An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that…
CVE-2026-78214Media (5.3)0.35%—29 sept 2026
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator…
CVE-2026-71899Media (6.5)0.23%—29 sept 2026
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows…
CVE-2026-71898Media (4.3)0.18%—29 sept 2026
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT…
CVE-2026-71897Media (4.3)0.18%—29 sept 2026
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions.…
CVE-2026-82804Alta (8.8)0.50%—29 sept 2026
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this…
CVE-2026-66083Media (6.5)0.23%—29 sept 2026
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access.…
CVE-2026-57590Alta (8.1)0.23%—24 sept 2026
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated…
CVE-2026-49050Alta (8.8)0.58%—25 ago 2026
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
CVE-2026-47340Media (6.5)0.55%—17 jun 2026
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are…
CVE-2026-42357Media (6.5)0.49%—17 jun 2026
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2.…
CVE-2026-41280Media (4.9)0.54%—17 jun 2026
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are…
CVE-2026-32967Crítica (9.1)0.55%—17 jun 2026
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes…
CVE-2026-32966Crítica (9.8)0.66%—17 jun 2026
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to…
CVE-2026-23902Alta (8.1)0.45%—24 abr 2026
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects…
CVE-2025-62233Media (6.3)0.54%—24 abr 2026
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can…
CVE-2025-62188Alta (7.5)0.52%—9 abr 2026
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database…
CVE-2024-43166Crítica (9.8)0.52%—3 sept 2025
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
CVE-2024-43115Alta (8.8)0.51%—3 sept 2025
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are…
CVE-2024-43202Crítica (9.8)2.1%—20 ago 2024
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
CVE-2024-30188Alta (8.1)6.0%—12 ago 2024
File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are…
CVE-2024-29831Alta (8.8)1.2%—12 ago 2024
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade…
CVE-2024-23320Alta (8.8)1.4%—23 feb 2024
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix…
CVE-2023-51770Alta (7.5)1.2%—20 feb 2024
Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
CVE-2023-50270Media (6.5)1.3%—20 feb 2024
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.
CVE-2023-49250Alta (7.3)0.70%—20 feb 2024
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache…
CVE-2023-49109Crítica (9.8)2.3%—20 feb 2024
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
CVE-2023-49299Alta (8.8)1.4%—30 dic 2023
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server.This issue affects Apache DolphinScheduler: until 3.1.9.…
CVE-2023-49620Media (6.5)1.1%—30 nov 2023
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0…
CVE-2023-49068Alta (7.5)1.1%—27 nov 2023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1. Users are recommended to upgrade to version 3.2.1, which…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services10
  2. T1078 Valid Accounts5
  3. T1190 Exploit Public-Facing Application5
  4. T1078.001 Default Accounts2
  5. T1552.007 Container API2
  6. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Apache