CVE-2023-50270: Apache DolphinScheduler: Session do not expire after password change
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
Other sources
Session Fixation Apache DolphinScheduler before version 3.2.1, which session is still valid after the password change.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
— GitHub
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50270?
CVE-2023-50270 is classified as a high severity vulnerability due to its potential to allow session fixation attacks after a password change.
How do I fix CVE-2023-50270?
To fix CVE-2023-50270, upgrade Apache DolphinScheduler to version 3.2.1 or later.
What products are affected by CVE-2023-50270?
CVE-2023-50270 affects Apache DolphinScheduler versions prior to 3.2.1.
What type of vulnerability is CVE-2023-50270?
CVE-2023-50270 is a session fixation vulnerability in Apache DolphinScheduler.
How does CVE-2023-50270 impact users?
CVE-2023-50270 allows attackers to maintain valid sessions even after legitimate users change their passwords, compromising account security.