First published: Tue Feb 20 2024(Updated: )
Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.dolphinscheduler:dolphinscheduler | <3.2.1 | 3.2.1 |
Apache DolphinScheduler | >=1.2.0<3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51770 is classified as a high-severity vulnerability due to its potential for arbitrary file read, which can expose sensitive information.
To fix CVE-2023-51770, users must upgrade Apache DolphinScheduler to version 3.2.1 or later.
CVE-2023-51770 affects all versions of Apache DolphinScheduler prior to 3.2.1.
CVE-2023-51770 is an arbitrary file read vulnerability in Apache DolphinScheduler.
If upgrading to version 3.2.1 is not possible, consider implementing access controls or other security measures to limit exposure until the upgrade can be performed.