CVE-2022-25598

HIGH7.5EPSS 1.1%

Uncontrolled Resource Consumption in Apache DolphinScheduler

Published: 3/31/2022Modified: 2/16/2024

Description

Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks. Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (5)