CVE-2025-62188

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. This issue affects Apache DolphinScheduler versions 3.1.*. Users are recommended to upgrade to: * version ≥ 3.2.0 if using 3.1.x As a temporary workaround, users who cannot upgrade immediately may restrict the exposed management endpoints by setting the following environment variable: ``` MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus ``` Alternatively, add the following configuration to the application.yaml file: ``` management:    endpoints:      web:         exposure:           include: health,metrics,prometheus ``` This issue has been reported as CVE-2023-48796: https://cveprocess.apache.org/cve5/CVE-2023-48796
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*

History

17 Apr 2026, 12:57

Type Values Removed Values Added
CPE cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*
First Time Apache dolphinscheduler
Apache
References () https://lists.apache.org/thread/ffrmkcwgr2lcz0f5nnnyswhpn3fytsvo - () https://lists.apache.org/thread/ffrmkcwgr2lcz0f5nnnyswhpn3fytsvo - Not Applicable
References () https://www.cve.org/CVERecord?id=CVE-2023-48796 - () https://www.cve.org/CVERecord?id=CVE-2023-48796 - Not Applicable

09 Apr 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

09 Apr 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 10:16

Updated : 2026-04-17 12:57


NVD link : CVE-2025-62188

Mitre link : CVE-2025-62188

CVE.ORG link : CVE-2025-62188


JSON object : View

Products Affected

apache

  • dolphinscheduler
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor