Apache DolphinScheduler
cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*
- < 3.4.1
A vulnerability in Apache DolphinScheduler prior to version 3.4.1 allows authenticated users with system login permissions to utilize tenants not defined on the platform during workflow execution. This incorrect authorization issue could lead to unauthorized access or manipulation of workflow processes.
Exploitation of this vulnerability could result in unauthorized use of tenants during workflow execution, potentially leading to incorrect workflow processing or resource allocation.
Users are advised to upgrade to Apache DolphinScheduler version 3.4.1 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.