CVE-2023-49250
Apache DolphinScheduler: Insecure TLS TrustManager used in HttpUtil
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.3EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
20 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.
This issue affects Apache DolphinScheduler: before 3.2.0.
Users are recommended to upgrade to version 3.2.1, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
Apache Software Foundation · Apache DolphinSchedulerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →