HIGH 7.3 Maven

Improper Certificate Validation in Apache DolphinScheduler

GHSA-37gx-jqx9-fwmg · CVE-2023-49250

Published · Modified

Description

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.

This issue affects Apache DolphinScheduler: before 3.2.1.

Users are recommended to upgrade to version 3.2.1, which fixes the issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes