CVE-2023-25601: Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authentication
On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version 3.0.0 to 3.1.1, you can turn off the python-gateway function by changing the value python-gateway.enabled=false in configuration file application.yaml. If you are using the python gateway, please upgrade to version 3.1.2 or above.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache DolphinScheduler vulnerability?
The vulnerability ID for this Apache DolphinScheduler vulnerability is CVE-2023-25601.
What is the severity of CVE-2023-25601?
The severity of CVE-2023-25601 is medium with a CVSS score of 4.3.
Which versions of Apache DolphinScheduler are affected by CVE-2023-25601?
Versions 3.0.0 through 3.1.1 of Apache DolphinScheduler are affected by CVE-2023-25601.
How can I fix CVE-2023-25601 in my Apache DolphinScheduler installation?
To fix CVE-2023-25601, you should update your Apache DolphinScheduler installation to version 3.1.2 or later.
Where can I find more information about CVE-2023-25601?
You can find more information about CVE-2023-25601 at the following references: [http://www.openwall.com/lists/oss-security/2023/04/20/10](http://www.openwall.com/lists/oss-security/2023/04/20/10) and [https://lists.apache.org/thread/25g77jqczp3t8cz56hk1p65q7m6c64rf](https://lists.apache.org/thread/25g77jqczp3t8cz56hk1p65q7m6c64rf).