CVE-2023-50270

MEDIUM

Apache DolphinScheduler 1.3.8-3.2.0 - Insufficient Session Expiration

Title source: llm
STIX 2.1

Description

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

References (4)

Core 4

Scores

CVSS v3 6.5
EPSS 0.0131
EPSS Percentile 67.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-384 CWE-613
Status published
Products (2)
apache/dolphinscheduler 1.3.8 - 3.2.1
org.apache.dolphinscheduler/dolphinscheduler 1.3.8 - 3.2.1Maven
Published Feb 20, 2024
Tracked Since Feb 18, 2026