First published: Wed Mar 30 2022(Updated: )
Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache DolphinScheduler | <2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25598 is a vulnerability in Apache DolphinScheduler that allows for Regular express Denial of Service (ReDoS) attacks.
CVE-2022-25598 has a severity level of high with a CVSS score of 7.5.
CVE-2022-25598 affects Apache DolphinScheduler by making the user registration process vulnerable to ReDoS attacks.
To fix CVE-2022-25598, users of Apache DolphinScheduler should upgrade to version 2.0.5 or higher.
You can find more information about CVE-2022-25598 on the Apache DolphinScheduler mailing list at [link](https://lists.apache.org/thread/hwnw7xr969sg5nv84wz75nfr2c76fl93).