Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c6cg-73p3-973h

Опубликовано: 27 нояб. 2023
Источник: github
Github: Прошло ревью

Описание

Apache DolphinScheduler Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.1.

Users are recommended to upgrade to version 3.2.1, which fixes the issue. At the time of disclosure of this advisory, this version has not yet been released. In the mean time, we recommend you make sure the logs are only available to trusted operators.

Пакеты

Наименование

org.apache.dolphinscheduler:dolphinscheduler-api

maven
Затронутые версииВерсия исправления

< 3.2.1

3.2.1

EPSS

Процентиль: 37%
0.0016
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue. At the time of disclosure of this advisory, this version has not yet been released. In the mean time, we recommend you make sure the logs are only available to trusted operators.

EPSS

Процентиль: 37%
0.0016
Низкий

Дефекты

CWE-200