Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Dolphinscheduler
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13922 1 Apache 1 Dolphinscheduler 2023-11-07 4.0 MEDIUM 6.5 MEDIUM
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
CVE-2022-25598 1 Apache 1 Dolphinscheduler 2023-07-12 5.0 MEDIUM 7.5 HIGH
Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.