Description
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
Affected products
- Apache Software Foundation / Apache DolphinSchedulerApache DolphinScheduler – 1.3.2