Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
Software | From | Fixed in |
---|---|---|
apache / dolphinscheduler | 1.2.0 | 1.2.0.x |
apache / dolphinscheduler | 1.2.1 | 1.2.1.x |
apache / dolphinscheduler | 1.3.1 | 1.3.1.x |
![]() |
- | 1.3.2 |