Apache DolphinScheduler Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.1.

Users are recommended to upgrade to version 3.2.1, which fixes the issue. At the time of disclosure of this advisory, this version has not yet been released. In the mean time, we recommend you make sure the logs are only available to trusted operators.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2023-11-27 12:30:55 UTC
Updated
2023-11-28 20:51:58 UTC
GitHub reviewed
2023-11-28 20:51:58 UTC
NVD published
2023-11-27

EPSS Score

Score Percentile
0.16% 37.41%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
maven org.apache.dolphinscheduler:dolphinscheduler-api < 3.2.1 3.2.1

References

cvelogic Threat Intelligence