CVE-2022-26885: Apache DolphinScheduler config file read by task risk
Published Nov 24, 2022
·Updated
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
Affected Software
1 affected component
Apache Dolphinscheduler<2.0.6
Event History
Nov 24, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-26885?
CVE-2022-26885 is a vulnerability that allows for database password disclosure when using tasks to read config files in Apache DolphinScheduler.
2
What is the severity of CVE-2022-26885?
CVE-2022-26885 has a severity rating of 7.5 (High).
3
How does CVE-2022-26885 affect Apache DolphinScheduler?
CVE-2022-26885 affects Apache DolphinScheduler versions up to (but not including) 2.0.6.
4
How can I fix CVE-2022-26885?
To fix CVE-2022-26885, it is recommended to upgrade Apache DolphinScheduler to version 2.0.6 or higher.
5
Where can I find more information about CVE-2022-26885?
You can find more information about CVE-2022-26885 at the following reference link: [https://lists.apache.org/thread/z7084r9cs2r26cszkkgjqpb5bhnxqssp]