Apache / Dolphinscheduler
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-49050 | Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens | HIGH | 8.8 | Aug 25, 2026 |
| CVE-2026-47340 | Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not… | MEDIUM | 6.5 | Jun 17, 2026 |
| CVE-2026-32967 | Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks | CRITICAL | 9.1 | Jun 17, 2026 |
| CVE-2026-42357 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have perm… | MEDIUM | 6.5 | Jun 17, 2026 |
| CVE-2026-41280 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects | MEDIUM | 4.9 | Jun 17, 2026 |
| CVE-2026-32966 | Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure | CRITICAL | 9.8 | Jun 17, 2026 |
| CVE-2026-23902 | Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution. | HIGH | 8.1 | Apr 24, 2026 |
| CVE-2025-62233 | Apache DolphinScheduler: Deserialization of untrusted data in RPC | MEDIUM | 6.3 | Apr 24, 2026 |
| CVE-2025-62188 | Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint. | HIGH | 7.5 | Apr 9, 2026 |
| CVE-2024-43166 | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgr… | CRITICAL | 9.8 | Sep 3, 2025 |
| CVE-2024-43115 | Apache DolphinScheduler: Alert Script Attack | HIGH | 8.8 | Sep 3, 2025 |
| CVE-2024-43202 | Apache DolphinScheduler: Remote Code Execution Vulnerability | CRITICAL | 9.3 | Aug 20, 2024 |
| CVE-2024-30188 | Apache DolphinScheduler: Resource File Read And Write Vulnerability | HIGH | 8.6 | Aug 9, 2024 |
| CVE-2024-29831 | Apache DolphinScheduler: RCE by arbitrary js execution | HIGH | 8.7 | Aug 9, 2024 |
| CVE-2024-23320 | Apache DolphinScheduler: Arbitrary js execution as root for authenticated users | HIGH | 8.7 | Feb 23, 2024 |
| CVE-2023-51770 | Apache DolphinScheduler: Arbitrary File Read Vulnerability | HIGH | 7.5 | Feb 20, 2024 |
| CVE-2023-50270 | Apache DolphinScheduler: Session do not expire after password change | MEDIUM | 6.5 | Feb 20, 2024 |
| CVE-2023-49250 | Apache DolphinScheduler: Insecure TLS TrustManager used in HttpUtil | HIGH | 7.3 | Feb 20, 2024 |
| CVE-2023-49109 | Remote Code Execution in Apache Dolphinscheduler | CRITICAL | 9.8 | Feb 20, 2024 |
| CVE-2023-49299 | Apache DolphinScheduler: Arbitrary js execute as root for authenticated users | HIGH | 8.7 | Dec 30, 2023 |
| CVE-2023-49620 | Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for | MEDIUM | 6.5 | Nov 30, 2023 |
| CVE-2023-49068 | Apache DolphinScheduler: Information Leakage Vulnerability | HIGH | 7.5 | Nov 27, 2023 |
| CVE-2023-48796 | Apache dolphinscheduler sensitive information disclosure | HIGH | 7.5 | Nov 24, 2023 |
| CVE-2023-25601 | Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authentication | MEDIUM | 4.3 | Apr 20, 2023 |
| CVE-2022-45875 | Apache DolphinScheduler: Remote command execution Vulnerability in script alert plugin | CRITICAL | 9.3 | Jan 4, 2023 |
Showing 1 to 25 of 33 CVEs