A missing authorization vulnerability exists in the API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to acce
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Apache Software Foundation | Apache DolphinScheduler | 3.2.0 ~ 3.4.3 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-102495 | Apache XMLSchema: Denial of service through unbounded recursion when resolving schema impo | |
| CVE-2026-91012 | Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalatio | |
| CVE-2026-91048 | Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege esc | |
| CVE-2026-91085 | Apache Karaf: config:install missing ACL entry allows privilege escalation to admin | |
| CVE-2026-92142 | Apache Karaf: Authorization bypass in JMX MBean lifecycle operations | |
| CVE-2026-81914 | Apache Airflow Google provider 查询注入漏洞 | |
| CVE-2026-81862 | Airflow Teradata插件云存储凭据泄露漏洞 | |
| CVE-2026-81930 | Apache Airflow Snowflake provider 令牌重定向漏洞 | |
| CVE-2026-86843 | Airflow Teradata插件SQL注入漏洞 | |
| CVE-2026-71897 | Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and ba | |
| CVE-2026-102496 | Apache XMLSchema: Denial of service through deeply nested schema structures | |
| CVE-2026-102497 | Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker | |
| CVE-2026-66083 | Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasourc | |
| CVE-2026-82804 | Apache DolphinScheduler 告警脚本命令注入漏洞 | |
| CVE-2026-81569 | Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized | |
| CVE-2026-78214 | Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths | |
| CVE-2026-71898 | Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute |
暂无评论