ZeroHour

CVE-2020-13922

CVSS 3.1
6.5 medium
EPSS
2%p76
Published
()
Modified
Description

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

Vendors
apache
Products
dolphinscheduler
Weakness
CWE-264, CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.