Medium severity6.5NVD Advisory· Published Jan 11, 2021· Updated Jun 17, 2026
CVE-2020-13922
CVE-2020-13922
Description
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.dolphinscheduler:dolphinscheduler-apiMaven | < 1.3.2 | 1.3.2 |
Affected products
5Apache DolphinScheduler+ 3 more
- (no CPE)range: Apache DolphinScheduler
- cpe:2.3:a:apache:dolphinscheduler:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:dolphinscheduler:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:dolphinscheduler:1.3.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-qhh5-9738-g9mxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-13922ghsaADVISORY
- github.com/apache/incubator-dolphinscheduler/commit/b8a9e2e00f2f207ae60c913a7173b59405ff95f1ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-dolphinscheduler/PYSEC-2021-876.yamlghsaWEB
- www.mail-archive.com/announce%40apache.org/msg06076.htmlnvdWEB
- www.mail-archive.com/[email protected]/msg06076.htmlghsaWEB
News mentions
0No linked articles in our index yet.