Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for
CVE-2023-49620

6.5MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
30 November 2023

Summary

Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability

Affected Version(s)

Apache DolphinScheduler 2.0.0 < 3.1.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuanheng Lab of zhongfu
.