Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors may include sensitive data such as database credentials. Users who can't upgrade to the fixed version can also set environment variable `MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus` to workaround this, or add the following section in the `application.yaml` file ``` management:   endpoints:     web:       exposure:         include: health,metrics,prometheus ``` This issue affects Apache DolphinScheduler: from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2, which fixes the issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2023-11-24T07:56:43.542Z

Updated: 2024-08-02T21:46:27.235Z

Reserved: 2023-11-20T03:53:27.700Z

Link: CVE-2023-48796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-24T08:15:20.810

Modified: 2024-11-21T08:32:27.867

Link: CVE-2023-48796

cve-icon Redhat

No data.