Apache DolphinScheduler Missing Authorization vulnerability
Moderate severity
GitHub Reviewed
Published
Nov 30, 2023
to the GitHub Advisory Database
•
Updated Dec 5, 2023
Package
Affected versions
< 3.1.0
Patched versions
3.1.0
Description
Published by the National Vulnerability Database
Nov 30, 2023
Published to the GitHub Advisory Database
Nov 30, 2023
Reviewed
Nov 30, 2023
Last updated
Dec 5, 2023
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability
References