Apache DolphinScheduler 存在一个授权漏洞,允许已认证的非管理员用户获取本应由管理员管理的集群配置中的 Kubernetes 配置数据(kubeconfig)。泄露的 kubeconfig 数据包含凭据,攻击者可能利用这些凭据绕过 DolphinScheduler,直接访问 Kubernetes API。 该漏洞的影响程度取决于所泄露凭据的权限范围。如果 kubeconfig 提供 cluster-admin 或具有广泛特权的服务账号访问权限,攻击者可能读取 Kubernetes Secret
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache DolphinScheduler | 3.1.0 ~ 3.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71896 | Apache DolphinScheduler: Missing Authorization Checks Allow Unauthorized Disclosure of Use | |
| CVE-2026-71183 | Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Info | |
| CVE-2026-66087 | Apache DolphinScheduler: Project Authorization Bypass in the Task instance stop/savepoint | |
| CVE-2026-66084 | Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream | |
| CVE-2026-66082 | Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (sch |
No comments yet