VYPR
Medium severity6.5NVD Advisory· Published Jan 11, 2021· Updated Jun 17, 2026

CVE-2020-13922

CVE-2020-13922

Description

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.dolphinscheduler:dolphinscheduler-apiMaven
< 1.3.21.3.2

Affected products

5

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.