Apache DolphinScheduler 存在一个授权漏洞。经过身份验证的用户可通过 /dolphinscheduler/users/list-all 接口,在无需相应权限的情况下获取其他用户的账户信息。 该接口在返回用户账户信息前未执行必要的授权检查。因此,已认证用户可访问其无权查看的账户信息。 成功利用此漏洞可能导致敏感用户信息泄露,并辅助攻击者进行账户枚举。 该问题影响 Apache DolphinScheduler 3.4.3 之前的版本。 建议用户升级至修复此问题的 3.4.3 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache DolphinScheduler | 0 ~ 3.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71895 | Apache DolphinScheduler: Missing Authorization Checks Allow Non-Admin Users to Retrieve Ku | |
| CVE-2026-71183 | Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Info | |
| CVE-2026-66087 | Apache DolphinScheduler: Project Authorization Bypass in the Task instance stop/savepoint | |
| CVE-2026-66084 | Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstream | |
| CVE-2026-66082 | Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (sch |
No comments yet