CVE-2023-50270

MEDIUM

Apache DolphinScheduler 1.3.8-3.2.0 - Insufficient Session Expiration

Title source: llm
STIX 2.1

Description

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

References (4)

Core 4

Scores

CVSS v3 6.5
EPSS 0.0131
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-613 CWE-384
Status published
Products (2)
apache/dolphinscheduler 1.3.8 - 3.2.1
org.apache.dolphinscheduler/dolphinscheduler 1.3.8 - 3.2.1Maven
Published Feb 20, 2024
Tracked Since Feb 18, 2026