Логотип exploitDog
bind:CVE-2023-48796
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-48796

Количество 2

Количество 2

nvd логотип

CVE-2023-48796

около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors may include sensitive data such as database credentials. Users who can't upgrade to the fixed version can also set environment variable `MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus` to workaround this, or add the following section in the `application.yaml` file ``` management:   endpoints:     web:       exposure:         include: health,metrics,prometheus ``` This issue affects Apache DolphinScheduler: from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2, which fixes the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vvc-r4p4-qgrr

около 2 лет назад

Apache DolphinScheduler sensitive information disclosure

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-48796

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors may include sensitive data such as database credentials. Users who can't upgrade to the fixed version can also set environment variable `MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus` to workaround this, or add the following section in the `application.yaml` file ``` management:   endpoints:     web:       exposure:         include: health,metrics,prometheus ``` This issue affects Apache DolphinScheduler: from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2, which fixes the issue.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-4vvc-r4p4-qgrr

Apache DolphinScheduler sensitive information disclosure

CVSS3: 7.5
1%
Низкий
около 2 лет назад

Уязвимостей на страницу