Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
"https://github.com/pypa/advisory-database/blob/main/vulns/apache-dolphinscheduler/PYSEC-2021-876.yaml"