Tracker / CVE-2020-13922
CVE-2020-13922
Medium 6.5
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
Affected products and versions
| apache | dolphinscheduler |
|---|
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.