CVE-2023-49250
CVSS V2 None
CVSS V3 None
Description
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.
This issue affects Apache DolphinScheduler: before 3.2.0.
Users are recommended to upgrade to version 3.2.1, which fixes the issue.
Overview
- CVE ID
- CVE-2023-49250
- Assigner
- apache
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-20T10:00:06.733Z
- Last Modified Date
- 2024-02-20T10:00:06.733Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/apache/dolphinscheduler/pull/15288 | patch |
https://lists.apache.org/thread/wgs2jvhbmq8xnd6rmg0ymz73nyj7b3qn | vendor-advisory |
http://www.openwall.com/lists/oss-security/2024/02/20/1 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-49250 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49250 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 13:12:54 | Added to TrackCVE |