Missing Authorization
CVE-2023-49620
Summary
UDFDolphinScheduler versions prior to 3.1.0, the login user could delete the UDF function in the resource center unauthorized (which is almost used in sql task), with unauthorized access vulnerability (IDOR). We mark this CVE as moderate level because it still requires users to log in to operate.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- NONE
- NONE
CWE-862 - Missing Authorization
The missing authorization vulnerability occurs when a software program allows users to access privileged parts of the program without verifying the user credentials. Impact of such a vulnerability depends on the resources employed by the software, ranging from account takeover to sensitive information exposure, denial of service, and complete system takeover.
References
Advisory Timeline
- Published