CVE-2023-50270

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/02/2024
Last modified:
18/03/2025

Description

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.<br /> <br /> Users are recommended to upgrade to version 3.2.1, which fixes this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* 1.3.8 (including) 3.2.1 (excluding)