« Volver al listado

CVE-2025-62188

Estado: AnalizadaAlta (7.5)—

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.

This vulnerability may allow unauthorized actors to access sensitive information, including database credentials.

This issue affects Apache DolphinScheduler versions 3.1.*.

Users are recommended to upgrade to:

As a temporary workaround, users who cannot upgrade immediately may restrict the exposed management endpoints by setting the following environment variable:

``` MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus ```

Alternatively, add the following configuration to the application.yaml file:

Leer descripción completaMostrar menos

``` management:    endpoints:      web:         exposure:           include: health,metrics,prometheus ```

This issue has been reported as CVE-2023-48796:

https://cveprocess.apache.org/cve5/CVE-2023-48796

Detalles técnicos trazas, registros y código del informe original
  *  version ≥ 3.2.0 if using 3.1.x

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de exposición de información en endpoints de gestión de DolphinScheduler (CWE-200). Vector CVSS AV:N/AC:L/PR:N/UI:N indica acceso remoto sin privilegios. El atacante accede a credenciales de base de datos y datos sensibles mediante endpoints web expuestos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-62188",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-62188",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-09T13:57:14.827090Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache DolphinScheduler",
          "versions": [
            {
              "status": "affected",
              "version": "3.1.0",
              "lessThan": "3.2.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-09T10:16:20.260",
  "references": [
    {
      "url": "https://lists.apache.org/thread/ffrmkcwgr2lcz0f5nnnyswhpn3fytsvo",
      "tags": [
        "Not Applicable"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-48796",
      "tags": [
        "Not Applicable"
      ],
      "source": "security@apache.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.\n\nThis vulnerability may allow unauthorized actors to access sensitive information, including database credentials.\n\n\nThis issue affects Apache DolphinScheduler versions 3.1.*.\n\n\nUsers are recommended to upgrade to:\n\n\n\n\n\n\n\n  *  version ≥ 3.2.0 if using 3.1.x\n\n\n\n\n\n\nAs a temporary workaround, users who cannot upgrade immediately may restrict the exposed management endpoints by setting the following environment variable:\n\n\n```\nMANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus\n```\n\nAlternatively, add the following configuration to the application.yaml file:\n\n\n```\nmanagement:\n   endpoints:\n     web:\n        exposure:\n          include: health,metrics,prometheus\n```\n\nThis issue has been reported as CVE-2023-48796:\n\n https://cveprocess.apache.org/cve5/CVE-2023-48796"
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de exposición de información sensible a un actor no autorizado en Apache DolphinScheduler.\n\nEsta vulnerabilidad puede permitir a actores no autorizados acceder a información sensible, incluyendo credenciales de base de datos.\n\nEste problema afecta a las versiones 3.1.* de Apache DolphinScheduler.\n\nSe recomienda a los usuarios actualizar a:\n\n  *  la versión ? 3.2.0 si se utiliza la 3.1.x\n\nComo solución alternativa temporal, los usuarios que no puedan actualizar de inmediato pueden restringir los puntos finales de gestión expuestos configurando la siguiente variable de entorno:\n\n'''\nMANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus\n'''\n\nAlternativamente, añada la siguiente configuración al archivo application.yaml:\n\n'''\nmanagement:\n   endpoints:\n     web:\n        exposure:\n          include: health,metrics,prometheus\n'''\n\nEste problema ha sido reportado como CVE-2023-48796:\n\n https://cveprocess.apache.org/cve5/CVE-2023-48796"
    }
  ],
  "lastModified": "2026-09-30T22:10:00.273",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "807E36C9-E326-491F-9E04-B2589F2C72D3",
              "versionEndExcluding": "3.2.0",
              "versionStartIncluding": "3.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}