CVE-2023-25601

CVE-2023-25601: Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authentication

Vendor Apache Software Foundation
Product Apache DolphinScheduler
Weakness CWE-287 · Improper authentication
Published April 20, 2023
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version 3.0.0 to 3.1.1, you can turn off the python-gateway function by changing the value `python-gateway.enabled=false` in configuration file `application.yaml`. If you are using the python gateway, please upgrade to version 3.1.2 or above.

Key dates

Disclosure timeline

April 20, 2023 CVE published
February 13, 2025 Record updated