Junglewise Threat Intelligence

CVE-2022-25598: PYSEC-2022-176 - Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users

CVE-2022-25598 · Severity: low · CVSS 3.1 · Published 2022-03-30

Technologies: apache-dolphinscheduler (PyPI), org.apache.dolphinscheduler:dolphinscheduler (Maven). Vendors: PyPI, Maven.

Executive brief

Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

Affected products

  • PyPI apache-dolphinscheduler
  • Maven org.apache.dolphinscheduler:dolphinscheduler

Related threats