Skip to content

Apache DolphinScheduler Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Moderate severity GitHub Reviewed Published Nov 27, 2023 to the GitHub Advisory Database • Updated Nov 28, 2023

Package

maven org.apache.dolphinscheduler:dolphinscheduler-api (Maven)

Affected versions

< 3.2.1

Patched versions

3.2.1

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.1.

Users are recommended to upgrade to version 3.2.1, which fixes the issue. At the time of disclosure of this advisory, this version has not yet been released. In the mean time, we recommend you make sure the logs are only available to trusted operators.

References

Published by the National Vulnerability Database Nov 27, 2023
Published to the GitHub Advisory Database Nov 27, 2023
Last updated Nov 28, 2023
Reviewed Nov 28, 2023

Severity

Moderate

Weaknesses

CVE ID

CVE-2023-49068

GHSA ID

GHSA-c6cg-73p3-973h
Checking history
See something to contribute? Suggest improvements for this vulnerability.