CVE-2022-26884: Apache DolphinScheduler exposes files without authentication
Published Oct 28, 2022
·Updated
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
Affected Software
1 affected component
Apache Dolphinscheduler<2.0.6
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-26884?
The severity of CVE-2022-26884 is medium, with a severity value of 6.5.
2
How does CVE-2022-26884 affect Apache DolphinScheduler?
CVE-2022-26884 allows users to read any files by log server in Apache DolphinScheduler.
3
What is the recommended version of Apache DolphinScheduler to address CVE-2022-26884?
Users should upgrade Apache DolphinScheduler to version 2.0.6 or higher to fix CVE-2022-26884.
4
Are there any references for CVE-2022-26884?
Yes, you can find references for CVE-2022-26884 at the following links: [Openwall](http://www.openwall.com/lists/oss-security/2022/10/28/2) and [Apache Mailing List](https://lists.apache.org/thread/xfdst5y4hnrm2ntmc5jzrgmw2htyyb9c).
5
What is the CWE category for CVE-2022-26884?
CVE-2022-26884 falls under CWE category 22.