First published: Tue Nov 01 2022(Updated: )
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache DolphinScheduler | <3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-34662.
The severity of CVE-2022-34662 is medium, with a severity value of 6.5.
The vulnerability CVE-2022-34662 manifests when users add resources to the resource center with a relation path, causing path traversal issues.
CVE-2022-34662 affects Apache DolphinScheduler versions up to, but not including, 3.0.0.
To fix the vulnerability CVE-2022-34662, you should upgrade to version 3.0.0 or higher of Apache DolphinScheduler.