Medium severity6.5NVD Advisory· Published Feb 20, 2024· Updated Jun 17, 2026
CVE-2023-50270
CVE-2023-50270
Description
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.dolphinscheduler:dolphinschedulerMaven | >= 1.3.8, < 3.2.1 | 3.2.1 |
Affected products
3cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:*range: >=1.3.8,<3.2.1
- (no CPE)range: 1.3.8
Patches
Vulnerability mechanics
References
7- github.com/apache/dolphinscheduler/pull/15219nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-vjqc-g788-f378ghsaADVISORY
- lists.apache.org/thread/94prw8hyk60vvw7s6cs3tr708qzqlwl6nvdVendor AdvisoryWEB
- lists.apache.org/thread/lmnf21obyos920dnvbfpwq29c1sd2r9rnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-50270ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/02/20/3nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/02/20/3ghsaWEB
News mentions
0No linked articles in our index yet.