AI analysis
Apache DolphinScheduler before 3.4.3 does not properly enforce authorization on the /datasources/unauth-datasource endpoint. An already authenticated user can call that endpoint and retrieve information about data sources they are not allowed to access, which can include configuration details and other sensitive metadata depending on the fields returned. The flaw is an authorization gap on a data-source lookup function (CWE-306), not a fully unauthenticated remote code execution issue, and it has not yet received a CVSS score. It affects deployments of Apache DolphinScheduler older than 3.4.3. There is no known public proof-of-concept and it is not listed in CISA KEV, so exploitation is none known.
What to do: Upgrade Apache DolphinScheduler to 3.4.3 or later. Until then, limit which accounts can reach the API and review access logs for calls to /datasources/unauth-datasource, then rotate any credentials that may have been exposed in data-source configuration.
Affected
| Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.