CVE-2023-49250

CVE-2023-49250: Apache DolphinScheduler: Insecure TLS TrustManager used in HttpUtil

Vendor Apache Software Foundation
Product Apache DolphinScheduler
Weakness CWE-295
Published February 20, 2024
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache DolphinScheduler: before 3.2.0. Users are recommended to upgrade to version 3.2.1, which fixes the issue.

Key dates

Disclosure timeline

February 20, 2024 CVE published
February 13, 2025 Record updated