Executive brief
Apache DolphinScheduler, a workflow orchestration platform, contains a security flaw in its data source management interface. An unauthorized person could exploit this to view sensitive configuration details and metadata for various connected data sources. This could lead to the exposure of database connection information and potentially allow further access to corporate data systems.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the DataSource API of Apache DolphinScheduler. The affected component, specifically within the dolphinscheduler-api package, fails to perform necessary authorization checks when a user attempts to access data source information. A remote, unauthenticated attacker can exploit this flaw over the network to retrieve arbitrary data source metadata. This disclosure can include sensitive connection details used by the scheduler to interact with external databases and services. The issue is resolved in version 3.4.2.
Affected products
- Apache DolphinScheduler < 3.4.2
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-17: patched: Version 3.4.2 released