CVE-2023-49620

Source
https://cve.org/CVERecord?id=CVE-2023-49620
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49620.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-49620
Aliases
Published
2023-11-30T08:17:01.765Z
Modified
2026-07-15T01:49:03.519220014Z
Summary
Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for
Details

Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability

Database specific
{
    "cwe_ids": [
        "CWE-862"
    ],
    "cna_assigner": "apache",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49620.json"
}
References

Affected packages

Git / github.com/apache/dolphinscheduler

Affected ranges

Type
GIT
Repo
https://github.com/apache/dolphinscheduler
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "cpe": "cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "3.1.0"
        },
        {
            "introduced": "0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49620.json"