Description
Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.
Remediation
References
https://lists.apache.org/thread/hwnw7xr969sg5nv84wz75nfr2c76fl93
Related Vulnerabilities
CVE-2017-12617 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-24432 Vulnerability in maven package io.jenkins.plugins:macstadium-orka
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.13
CVE-2019-10412 Vulnerability in maven package com.inedo.proget:inedo-proget
CVE-2020-11969 Vulnerability in maven package org.apache.tomee:openejb-lite