Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://github.com/apache/dolphinscheduler/pull/15219 | Issue Tracking Patch |
https://github.com/apache/dolphinscheduler/pull/15219 | Issue Tracking Patch |
https://lists.apache.org/thread/94prw8hyk60vvw7s6cs3tr708qzqlwl6 | Vendor Advisory |
https://lists.apache.org/thread/94prw8hyk60vvw7s6cs3tr708qzqlwl6 | Vendor Advisory |
https://lists.apache.org/thread/lmnf21obyos920dnvbfpwq29c1sd2r9r | Vendor Advisory |
https://lists.apache.org/thread/lmnf21obyos920dnvbfpwq29c1sd2r9r | Vendor Advisory |
https://www.openwall.com/lists/oss-security/2024/02/20/3 | Mailing List Third Party Advisory |
https://www.openwall.com/lists/oss-security/2024/02/20/3 | Mailing List Third Party Advisory |
Configurations
History
18 Mar 2025, 17:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.apache.org/thread/lmnf21obyos920dnvbfpwq29c1sd2r9r - Vendor Advisory | |
References | () https://www.openwall.com/lists/oss-security/2024/02/20/3 - Mailing List, Third Party Advisory | |
References | () https://lists.apache.org/thread/94prw8hyk60vvw7s6cs3tr708qzqlwl6 - Vendor Advisory | |
References | () https://github.com/apache/dolphinscheduler/pull/15219 - Issue Tracking, Patch | |
CPE | cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* | |
First Time |
Apache dolphinscheduler
Apache |
23 Feb 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
20 Feb 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Feb 2024, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-20 10:15
Updated : 2025-03-18 17:38
NVD link : CVE-2023-50270
Mitre link : CVE-2023-50270
JSON object : View
Products Affected
apache
- dolphinscheduler
CWE
No CWE.