CVE-2023-49620

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-49620
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49620.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-49620
Aliases
Published
2023-11-30T09:15:07Z
Modified
2024-09-03T04:36:17.019138Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability

References

Affected packages

Git / github.com/apache/incubator-dolphinscheduler

Affected ranges

Type
GIT
Repo
https://github.com/apache/incubator-dolphinscheduler
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0-preview
1.3.1
1.3.3