« Volver al listado

CVE-2020-13922

Estado: ModificadaMedia (6.5)—

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-13922",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache DolphinScheduler",
          "versions": [
            {
              "status": "affected",
              "version": "Apache DolphinScheduler",
              "lessThan": "1.3.2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-11T10:15:13.283",
  "references": [
    {
      "url": "https://www.mail-archive.com/announce%40apache.org/msg06076.html",
      "source": "security@apache.org"
    },
    {
      "url": "https://www.mail-archive.com/announce%40apache.org/msg06076.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface."
    },
    {
      "lang": "es",
      "value": "Las versiones de Apache DolphinScheduler anteriores a 1.3.2, permitían a un usuario normal bajo cualquier inquilino anular la contraseña de otro usuario por medio de la interfaz de la API"
    }
  ],
  "lastModified": "2026-06-17T02:53:54.237",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:dolphinscheduler:1.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F2A61CF-878B-430F-81B0-EBFA5CAC268B"
            },
            {
              "criteria": "cpe:2.3:a:apache:dolphinscheduler:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "008CAFE2-E837-4945-95A0-2BF8667AD14F"
            },
            {
              "criteria": "cpe:2.3:a:apache:dolphinscheduler:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C6F5E98-BC52-4B9F-B30A-C31E0E5CBB9D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}