CVE-2023-50270: Apache Dolphinscheduler
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.
Affected products
- Apache Dolphinscheduler: from 1.3.8, before 3.2.1 (fixed in 3.2.1)
Published 2024-02-20. Last modified 2026-06-17.