CVE-2023-49620
Apache DolphinScheduler Missing Authorization vulnerability
6.5
MEDIUM
CVSS 3.1
EPSS 1.1%
描述
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability
如何修補 CVE-2023-49620
要修補 CVE-2023-49620,請將受影響套件升級到下列已修補版本。
- —升級至 3.1.0 或更新版本
- —升級至 3.1.0 或更新版本
- —升級至 3.1.0 或更新版本
- —升級至 3.1.0 或更新版本
CVE-2023-49620 正在被利用嗎?
低 — EPSS 為 1.1%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 3.1.0
- from 0, < 3.1.0
- from 0, < 3.1.0
- from 0, < 3.1.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |