CVE-2025-62233: Apache DolphinScheduler: Deserialization of untrusted data in RPC
Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module.
This issue affects Apache DolphinScheduler:
Version >= 3.2.0 and < 3.3.1.
Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and sending RPC requests to the DolphinScheduler Master/Worker nodes. Users are recommended to upgrade to version [3.3.1], which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62233?
CVE-2025-62233 is considered a critical vulnerability due to the potential for remote code execution through deserialization of untrusted data.
How do I fix CVE-2025-62233?
To fix CVE-2025-62233, upgrade Apache DolphinScheduler to version 3.3.1 or later, which addresses the vulnerability.
What versions of Apache DolphinScheduler are affected by CVE-2025-62233?
CVE-2025-62233 affects Apache DolphinScheduler versions from 3.2.0 up to, but not including, 3.3.1.
What are the potential impacts of CVE-2025-62233 if exploited?
If exploited, CVE-2025-62233 could allow attackers to execute arbitrary code on the Master or Worker nodes.
Who can exploit CVE-2025-62233?
CVE-2025-62233 can be exploited by attackers who have access to the Master or Worker nodes of Apache DolphinScheduler.