https://seclists.org/oss-sec/2023/q4/252: CVE-2023-49620: Apache DolphinScheduler: Authenticated users could delete UDFs in resouece center they were not authorized
Published Nov 30, 2023
·Updated
Affected Software
1 affected component
Apache Dolphinscheduler<3.1.0
Frequently Asked Questions
1
What is the severity of CVE-2023-49620?
The severity of CVE-2023-49620 is classified as moderate.
2
Which versions of Apache DolphinScheduler are affected by CVE-2023-49620?
Apache DolphinScheduler versions 2.0.0 and below 3.1.0 are affected by CVE-2023-49620.
3
What vulnerability does CVE-2023-49620 exploit?
CVE-2023-49620 exploits an unauthorized access vulnerability, specifically an IDOR, allowing users to delete UDF functions.
4
How can I mitigate CVE-2023-49620?
To mitigate CVE-2023-49620, upgrade Apache DolphinScheduler to version 3.1.0 or later.
5
What impact does CVE-2023-49620 have on users?
CVE-2023-49620 allows authenticated users to delete UDFs in the resource center that they are not authorized to access.