Medium
CVSS 6.5
Overview
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user unde...
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: