---
id: CVE-2025-62188
title: >-
  An Exposure of Sensitive Information to an Unauthorized Actor vulnerability
  exists in Apache DolphinScheduler.


  This vulnerability may allow unauthorized actors to access sensitive
  information, including database credentials.



  This issu…
summary: >-
  An Exposure of Sensitive Information to an Unauthorized Actor vulnerability
  exists in Apache DolphinScheduler.


  This vulnerability may allow unauthorized actors to access sensitive
  information, including database credentials.



  This issu…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: apache
product: dolphinscheduler
affected:
  - 'dolphinscheduler >= 3.1.0, < 3.2.0'
patched:
  - dolphinscheduler 3.2.0
published: '2026-04-09'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62188'
references:
  - url: 'https://lists.apache.org/thread/ffrmkcwgr2lcz0f5nnnyswhpn3fytsvo'
    label: security@apache.org
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-48796'
    label: security@apache.org
tags:
  - nvd
epss: 0.00521
epssPercentile: 0.42068
ingestedAt: '2026-09-30T22:27:27.749Z'
---

## Overview

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.

This vulnerability may allow unauthorized actors to access sensitive information, including database credentials.


This issue affects Apache DolphinScheduler versions 3.1.*.


Users are recommended to upgrade to:







  *  version ≥ 3.2.0 if using 3.1.x






As a temporary workaround, users who cannot upgrade immediately may restrict the exposed management endpoints by setting the following environment variable:


```
MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus
```

Alternatively, add the following configuration to the application.yaml file:


```
management:
   endpoints:
     web:
        exposure:
          include: health,metrics,prometheus
```

This issue has been reported as CVE-2023-48796:

 https://cveprocess.apache.org/cve5/CVE-2023-48796

## Affected

- `dolphinscheduler >= 3.1.0, < 3.2.0`

## Remediation

Upgrade past the affected range:

- `dolphinscheduler 3.2.0`
