Severity: moderate 

Affected versions:

- Apache DolphinScheduler before 3.4.3

Description:

The /datasources/unauth-datasource endpoint does not properly enforce data 
source authorization. An authenticated user can invoke this endpoint to obtain 
information about data sources they are not authorized to access. This may 
expose data source configuration and other sensitive metadata, depending on the 
fields returned by the endpoint.



This issue affects Apache DolphinScheduler: before 3.4.3.



Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Credit:

n0mi1k (finder)
meifukun (finder)
Mingsheng Lin (finder)
Thành Nguyễn (finder)
Raphael Zanarelli (finder)
geo-chen (finder)

References:

https://dolphinscheduler.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-66083

Reply via email to