CVE-2023-49068

Severity
7.5HIGH
EPSS
0.2%
top 63.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue. At the time of disclosure of this advisory, this version has not yet been released. In the mean time, we recommend you make sure the logs are only available to trusted operators.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Patches

🔴Vulnerability Details

3
OSV
Apache DolphinScheduler Exposure of Sensitive Information to an Unauthorized Actor vulnerability2023-11-27
CVEList
Apache DolphinScheduler: Information Leakage Vulnerability2023-11-27
GHSA
Apache DolphinScheduler Exposure of Sensitive Information to an Unauthorized Actor vulnerability2023-11-27
CVE-2023-49068 (HIGH CVSS 7.5) | Exposure of Sensitive Information t | cvebase.io