Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 118 bronnen 1 kritiek 31 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-62233

MEDIUM · 6.3 CVSS Gepubliceerd: CWE-502

Beschrijving

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module.

This issue affects Apache DolphinScheduler: 

Version >= 3.2.0 and < 3.3.1.

Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and sending RPC requests to the DolphinScheduler Master/Worker nodes.
Users are recommended to upgrade to version [3.3.1], which fixes the issue.

Vendors

Apache

Affected products

Dolphinscheduler

References