AI analysis
Apache DolphinScheduler before 3.4.3 has an authentication bypass in how it decides whether Actuator endpoints require authentication. The check matches the incoming request path against protected Actuator paths, and a remote unauthenticated attacker can send a percent-encoded path so the request is not recognized as targeting a protected endpoint. Successful exploitation can expose operational or configuration information and, depending on which Actuator endpoints are enabled and how the application is configured, may allow access to sensitive management functionality. Anyone running an affected DolphinScheduler version with reachable Actuator endpoints is at risk. There is no known public proof of concept and no report of exploitation in the wild; the issue is not listed in CISA KEV and has not yet been scored.
What to do: Upgrade Apache DolphinScheduler to 3.4.3 or later. Until then, restrict network access to Actuator and management endpoints (for example with a reverse proxy or firewall) and review logs for requests to Actuator paths that use percent-encoding. After upgrading, confirm that sensitive Actuator endpoints still require authentication.
Affected
| Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated attacker can cause the security check to fail to recognize the request as targeting a protected endpoint. As a result, the attacker may bypass authentication and access otherwise restricted Actuator endpoints. Successful exploitation may expose operational or configuration information and, depending on the enabled endpoints and application configuration, allow access to sensitive management functionality. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.