Improper Certificate Validation in Apache DolphinScheduler
High severity
GitHub Reviewed
Published
Feb 20, 2024
to the GitHub Advisory Database
•
Updated Dec 2, 2024
Package
Affected versions
< 3.2.1
Patched versions
3.2.1
Description
Published by the National Vulnerability Database
Feb 20, 2024
Published to the GitHub Advisory Database
Feb 20, 2024
Reviewed
Feb 21, 2024
Last updated
Dec 2, 2024
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.
This issue affects Apache DolphinScheduler: before 3.2.1.
Users are recommended to upgrade to version 3.2.1, which fixes the issue.
References