CVE-2023-50270

MEDIUM

Apache Dolphinscheduler < 3.2.1 - Insufficient Session Expiration

Title source: rule
STIX 2.1

Description

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

Scores

CVSS v3 6.5
EPSS 0.0104
EPSS Percentile 77.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-613 CWE-384
Status published
Products (2)
apache/dolphinscheduler 1.3.8 - 3.2.1
org.apache.dolphinscheduler/dolphinscheduler 1.3.8 - 3.2.1Maven
Published Feb 20, 2024
Tracked Since Feb 18, 2026