CVE-2023-50270: Session Fixation Apache DolphinScheduler
6.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.62282%
CWE
Published
2/20/2024
Updated
3/3/2024
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.dolphinscheduler:dolphinscheduler | maven | >= 1.3.8, < 3.2.1 | 3.2.1 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The patch in PR#15219 explicitly adds session invalidation logic to UsersServiceImpl.updateUser and enhances SessionDaoImpl.deleteByUserId. The vulnerability stems from 1) not clearing sessions during password updates, and 2) incomplete session management infrastructure. The CWE-613 mapping confirms this is an insufficient session expiration issue where credential changes didn't terminate existing sessions.