CVE-2022-26884
published 2022-10-28CVE-2022-26884: Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.49%
71.0th percentile
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | dolphinscheduler | < 2.0.6 | 2.0.6 |
| apache_software_foundation | apache_dolphinscheduler | >= Apache DolphinScheduler < 2.0.6 | 2.0.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache DolphinScheduler vulnerable to Path Traversal
ghsa·2022-10-28
CVE-2022-26884 [MEDIUM] CWE-22 Apache DolphinScheduler vulnerable to Path Traversal
Apache DolphinScheduler vulnerable to Path Traversal
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
OSV
Apache DolphinScheduler vulnerable to Path Traversal
osv·2022-10-28
CVE-2022-26884 [MEDIUM] Apache DolphinScheduler vulnerable to Path Traversal
Apache DolphinScheduler vulnerable to Path Traversal
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
No detection rules found.
No public exploits indexed.
2022-10-28
Published