VDB
KO
CRITICAL 9.1

GHSA-85g9-8j9g-p486

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

Details

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.

This issue affects Apache DolphinScheduler: before 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.apache.dolphinscheduler:dolphinscheduler-api
Introduced in: 0 Fixed in: 3.4.2
Fix # pom.xml: bump <version>3.4.2</version> for org.apache.dolphinscheduler:dolphinscheduler-api

References