VDB
Sign up
MEDIUM6.5

PYSEC-2021-876

Details

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/apache-dolphinscheduler
Introduced in: 0

No fixed version published yet for apache-dolphinscheduler (pip). Pin to a known-safe version or switch to an alternative.

References