Severity: important 

Affected versions:

- Apache DolphinScheduler before 3.4.3

Description:

An authorization vulnerability in Apache DolphinScheduler allows authenticated 
users to obtain information about data sources they are not authorized to 
access through the /unauth-datasource and /authed-datasource endpoints.



These endpoints fail to enforce the required data source access controls and 
return sensitive connection information, including data source passwords. As a 
result, an authenticated user without permission to access a data source can 
retrieve its connection details and credentials.



Successful exploitation exposes sensitive data source information and may 
enable unauthorized access to the underlying databases using the disclosed 
credentials.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Credit:

Raphael Zanarelli (finder)

References:

https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-71183

Reply via email to