https://seclists.org/oss-sec/2024/q1/147: CVE-2023-50270: Apache DolphinScheduler: Session do not expire after password change
Published Feb 20, 2024
·Updated
Affected Software
1 affected component
Apache Dolphinscheduler>=1.3.8<3.2.0
Frequently Asked Questions
1
What is the severity of CVE-2023-50270?
The severity of CVE-2023-50270 is classified as important.
2
Which versions of Apache DolphinScheduler are affected by CVE-2023-50270?
Apache DolphinScheduler versions 1.3.8 through 3.2.0 are affected by CVE-2023-50270.
3
How do I fix CVE-2023-50270?
To fix CVE-2023-50270, users should upgrade to Apache DolphinScheduler version 3.2.1 or later.
4
What is the main issue addressed in CVE-2023-50270?
CVE-2023-50270 addresses a session fixation vulnerability where sessions remain valid after a password change.
5
When was CVE-2023-50270 published?
CVE-2023-50270 was published on February 20, 2024.