Rewterz
Rewterz Threat Advisory – CVE-2023-20873 – VMware Tanzu Spring Boot Vulnerability
April 25, 2023
Rewterz
Rewterz Threat Alert – STRRAT Malware – Active IOCs
April 25, 2023

Rewterz Threat Advisory – CVE-2023-25601 – Apache DolphinScheduler Vulnerability

Severity

High

Analysis Summary

CVE-2023-25601

Apache DolphinScheduler could allow a remote attacker to bypass security restrictions, caused by improper authentication validation by the python-gateway function. By sending a specially-crafted request using a socket bytes, an attacker could exploit this vulnerability to bypass access restrictions.

Impact

  • Security Bypass

Indicators Of Compromise

CVE

  • CVE-2023-25601

Affected Vendors

Apache

Affected Products

  • Apache DolphinScheduler 3.0.0
  • Apache DolphinScheduler 3.1.1

Remediation

Upgrade to the latest version of Apache DolphinScheduler, available from the Apache Website. 

Apache Website