CVE-2022-34662
Apache DolphinScheduler prior to 3.0.0 allows path traversal
- Published
- Nov 1, 2022
- Updated
- May 6, 2025
- Assigning CNA
- apache
- Evidence observed
- Aug 8, 2026
Apache DolphinScheduler prior to 3.0.0 allows path traversal
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NLow · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher
Proof-of-concept exploit for CVE-2022-34662 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in the workflow scheduler.
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.