CVE-2023-49620

Severity
6.5MEDIUM
EPSS
0.3%
top 43.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30

Description

Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Patches

🔴Vulnerability Details

3
GHSA
Apache DolphinScheduler Missing Authorization vulnerability2023-11-30
CVEList
Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for2023-11-30
OSV
Apache DolphinScheduler Missing Authorization vulnerability2023-11-30
CVE-2023-49620 (MEDIUM CVSS 6.5) | Before DolphinScheduler version 3.1 | cvebase.io