Rewterz Threat Update – Recent ‘HrServ.dll’ Web Shell Detected in APT Attack Targeting Afghan Government
November 27, 2023Rewterz Threat Advisory – Multiple Adobe Products Vulnerabilities
November 27, 2023Rewterz Threat Update – Recent ‘HrServ.dll’ Web Shell Detected in APT Attack Targeting Afghan Government
November 27, 2023Rewterz Threat Advisory – Multiple Adobe Products Vulnerabilities
November 27, 2023Severity
High
Analysis Summary
CVE-2023-48796
Apache DolphinScheduler could allow a remote attacker to obtain sensitive information, caused by improper authorization validation. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain database credentials information, and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2023-48796
Affected Vendors
Apache
Affected Products
- Apache DolphinScheduler 3.0.0
- Apache DolphinScheduler 3.0.1
Remediation
Upgrade to the latest version of Apache DolphinScheduler, available from the Apache Website.