GHSA-3jxw-cv35-2mmv

Suggest an improvement
Source
https://github.com/advisories/GHSA-3jxw-cv35-2mmv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-3jxw-cv35-2mmv/GHSA-3jxw-cv35-2mmv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3jxw-cv35-2mmv
Aliases
Published
2023-04-20T18:30:50Z
Modified
2024-02-16T08:14:50.225023Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Apache DolphinScheduler's python gateway suffered from improper authentication
Details

On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version 3.0.0 to 3.1.1, you can turn off the python-gateway function by changing the value python-gateway.enabled=false in configuration file application.yaml. If you are using the python gateway, please upgrade to version 3.1.2 or above.

Database specific
{
    "nvd_published_at": "2023-04-20T16:15:07Z",
    "cwe_ids": [
        "CWE-287"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-04-20T20:26:06Z"
}
References

Affected packages

Maven / org.apache.dolphinscheduler:dolphinscheduler-api

Package

Name
org.apache.dolphinscheduler:dolphinscheduler-api
View open source insights on deps.dev
Purl
pkg:maven/org.apache.dolphinscheduler/dolphinscheduler-api

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.1.2

Affected versions

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.1.1