CVE-2023-50270

Severity
6.5MEDIUM
EPSS
1.0%
top 22.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20

Description

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages3 packages

Patches

🔴Vulnerability Details

3
GHSA
Session Fixation Apache DolphinScheduler2024-02-20
OSV
Session Fixation Apache DolphinScheduler2024-02-20
CVEList
Apache DolphinScheduler: Session do not expire after password change2024-02-20
CVE-2023-50270 (MEDIUM CVSS 6.5) | Session Fixation Apache DolphinSche | cvebase.io