Vulnerabilities > Apache > Dolphinscheduler > 3.0.3

DATE CVE VULNERABILITY TITLE RISK
2023-12-30 CVE-2023-49299 Improper Input Validation vulnerability in Apache Dolphinscheduler
Improper Input Validation vulnerability in Apache DolphinScheduler.
network
low complexity
apache CWE-20
8.8
2023-11-30 CVE-2023-49620 Missing Authorization vulnerability in Apache Dolphinscheduler
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue.
network
low complexity
apache CWE-862
6.5
2023-11-27 CVE-2023-49068 Unspecified vulnerability in Apache Dolphinscheduler
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: before 3.2.1. Users are recommended to upgrade to version 3.2.1, which fixes the issue.
network
low complexity
apache
7.5