AI analysis
Apache DolphinScheduler before 3.4.3 has a missing authorization check (CWE-863) on the /dolphinscheduler/users/list-all endpoint. Any authenticated user can call that endpoint and receive other users' account information without the permissions that should be required. The disclosed data can expose sensitive account details and support account enumeration, but the flaw does not by itself grant unauthenticated access or remote code execution. Organizations running DolphinScheduler versions earlier than 3.4.3 are affected. There is no known public proof of concept, and the issue is not listed in CISA KEV.
What to do: Upgrade Apache DolphinScheduler to version 3.4.3 or later. Until then, restrict network access to the web API (especially /dolphinscheduler/users/list-all) to trusted administrators and review access logs for unexpected calls to that endpoint by ordinary authenticated users.
Affected
| Apache Software Foundation Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they are not authorized to view. Successful exploitation may expose sensitive user information and facilitate account enumeration. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.