Описание
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability
Ссылки
- Mailing ListThird Party Advisory
- Issue TrackingPatch
- Mailing ListVendor Advisory
- Mailing ListThird Party Advisory
- Issue TrackingPatch
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.0 (исключая)
cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00333
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 6.5
github
около 2 лет назад
Apache DolphinScheduler Missing Authorization vulnerability
EPSS
Процентиль: 56%
0.00333
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862