Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
During installation, installed file permissions are set to allow anyone to modify those files.