High severity7.5NVD Advisory· Published Nov 27, 2023· Updated Jun 17, 2026
CVE-2023-49068
CVE-2023-49068
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1.
Users are recommended to upgrade to version 3.2.1, which fixes the issue. At the time of disclosure of this advisory, this version has not yet been released. In the mean time, we recommend you make sure the logs are only available to trusted operators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.dolphinscheduler:dolphinscheduler-apiMaven | < 3.2.1 | 3.2.1 |
Affected products
3cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*range: <3.2.1
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
5- github.com/apache/dolphinscheduler/pull/15192nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-c6cg-73p3-973hghsaADVISORY
- lists.apache.org/thread/jn6kr6mjdgtfgpxoq9j8q4pkfsq8zmpqnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-49068ghsaADVISORY
- github.com/apache/dolphinscheduler/commit/7308888c703fbe227887d2426273100582096134ghsaWEB
News mentions
0No linked articles in our index yet.