6.5
CVSSv3

CVE-2020-13922

Published: 11/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Versions of Apache DolphinScheduler before 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache dolphinscheduler 1.2.1

apache dolphinscheduler 1.2.0

apache dolphinscheduler 1.3.1

Github Repositories

DSCVE-2020-13922 关于CVE-2020-13922安全漏洞的升级文件 根据当前版本替换lib目录下的jar包: 120版本 dolphinscheduler-api-120-SNAPSHOTjar 121版本 dolphinscheduler-api-121-SNAPSHOTjar