CVE-2025-62233

⚪ Do wiadomości

Deserializacja niezaufanych danych w Apache DolphinScheduler umożliwia atakującym kompromitację systemu.

CVSS
6.3
EPSS
0.5%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and sending RPC requests to the DolphinScheduler Master/Worker nodes. Users are recommended to upgrade to version [3.3.1], which fixes the issue.

deserialization Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2026-04-24 11:16:21 UTC
Ostatnia modyfikacja (NVD)2026-10-05 15:10:00 UTC
Referencje