First published: Thu Nov 24 2022(Updated: )
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache DolphinScheduler | <2.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26885 is a vulnerability that allows for database password disclosure when using tasks to read config files in Apache DolphinScheduler.
CVE-2022-26885 has a severity rating of 7.5 (High).
CVE-2022-26885 affects Apache DolphinScheduler versions up to (but not including) 2.0.6.
To fix CVE-2022-26885, it is recommended to upgrade Apache DolphinScheduler to version 2.0.6 or higher.
You can find more information about CVE-2022-26885 at the following reference link: [https://lists.apache.org/thread/z7084r9cs2r26cszkkgjqpb5bhnxqssp]