First published: Fri Oct 28 2022(Updated: )
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache DolphinScheduler | <2.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-26884 is medium, with a severity value of 6.5.
CVE-2022-26884 allows users to read any files by log server in Apache DolphinScheduler.
Users should upgrade Apache DolphinScheduler to version 2.0.6 or higher to fix CVE-2022-26884.
Yes, you can find references for CVE-2022-26884 at the following links: [Openwall](http://www.openwall.com/lists/oss-security/2022/10/28/2) and [Apache Mailing List](https://lists.apache.org/thread/xfdst5y4hnrm2ntmc5jzrgmw2htyyb9c).
CVE-2022-26884 falls under CWE category 22.