3.2.1
4 years ago
10 months ago
Known vulnerabilities in the org.apache.dolphinscheduler:dolphinscheduler-dao package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.apache.dolphinscheduler:dolphinscheduler-dao is an A visual DAG workflow scheduling system, dedicated to solving the complex dependencies in data processing. Affected versions of this package are vulnerable to Session Fixation. An attacker can hijack a user session by exploiting the fact that a session remains valid even after the user's password has been changed. How to fix Session Fixation? Upgrade | [,3.2.1) |
org.apache.dolphinscheduler:dolphinscheduler-dao is an A visual DAG workflow scheduling system, dedicated to solving the complex dependencies in data processing. Affected versions of this package are vulnerable to Remote Code Execution (RCE). An attacker can execute code remotely in the server due to deserialization of objectsR. Note: Related to CVE-2017-3523 How to fix Remote Code Execution (RCE)? Upgrade | [,1.3.0) |