Skip to main content

Missing Authorization

CVE-2023-49620

Severity Medium
Score 6.5/10

Summary

UDFDolphinScheduler versions prior to 3.1.0, the login user could delete the UDF function in the resource center unauthorized (which is almost used in sql task), with unauthorized access vulnerability (IDOR). We mark this CVE as moderate level because it still requires users to log in to operate.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • NONE

CWE-862 - Missing Authorization

The missing authorization vulnerability occurs when a software program allows users to access privileged parts of the program without verifying the user credentials. Impact of such a vulnerability depends on the resources employed by the software, ranging from account takeover to sensitive information exposure, denial of service, and complete system takeover.

Advisory Timeline

  • Published