ZeroHour

CVE-2023-50270

CVSS 3.1
6.5 medium
EPSS
1%p69
Published
()
Modified
Description

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

Vendors
apache
Products
dolphinscheduler
Weakness
CWE-613, CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.