Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37gx-jqx9-fwmg

Опубликовано: 20 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Improper Certificate Validation in Apache DolphinScheduler

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.

This issue affects Apache DolphinScheduler: before 3.2.1.

Users are recommended to upgrade to version 3.2.1, which fixes the issue.

Пакеты

Наименование

org.apache.dolphinscheduler:dolphinscheduler

maven
Затронутые версииВерсия исправления

< 3.2.1

3.2.1

EPSS

Процентиль: 38%
0.0017
Низкий

7.3 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.3
nvd
почти 2 года назад

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache DolphinScheduler: before 3.2.0. Users are recommended to upgrade to version 3.2.1, which fixes the issue.

EPSS

Процентиль: 38%
0.0017
Низкий

7.3 High

CVSS3

Дефекты

CWE-295