Описание
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
Ссылки
- Issue TrackingPatch
- Vendor Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Issue TrackingPatch
- Vendor Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.3.8 (включая) до 3.2.1 (исключая)
cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00799
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-613
CWE-384
Связанные уязвимости
EPSS
Процентиль: 74%
0.00799
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-613
CWE-384