Skip to content

Improper Certificate Validation in Apache DolphinScheduler

High severity GitHub Reviewed Published Feb 20, 2024 to the GitHub Advisory Database • Updated Feb 21, 2024

Package

maven org.apache.dolphinscheduler:dolphinscheduler (Maven)

Affected versions

< 3.2.1

Patched versions

3.2.1

Description

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.

This issue affects Apache DolphinScheduler: before 3.2.1.

Users are recommended to upgrade to version 3.2.1, which fixes the issue.

References

Published by the National Vulnerability Database Feb 20, 2024
Published to the GitHub Advisory Database Feb 20, 2024
Reviewed Feb 21, 2024
Last updated Feb 21, 2024

Severity

High

EPSS score

0.045%
(16th percentile)

Weaknesses

CVE ID

CVE-2023-49250

GHSA ID

GHSA-37gx-jqx9-fwmg
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.