Apache

Dolphinscheduler

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 08.10.2026 08:39:21
  • Zuletzt bearbeitet 08.10.2026 17:25:38

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce...

  • EPSS 0.17%
  • Veröffentlicht 08.10.2026 08:37:21
  • Zuletzt bearbeitet 08.10.2026 17:25:38

An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that m...

  • EPSS 0.15%
  • Veröffentlicht 08.10.2026 08:34:48
  • Zuletzt bearbeitet 08.10.2026 17:25:38

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail t...

  • EPSS 0.16%
  • Veröffentlicht 08.10.2026 08:29:43
  • Zuletzt bearbeitet 08.10.2026 21:18:02

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the  * /dolphinscheduler/projects/{projectCode}/task-instances/{taskIns...

  • EPSS 0.18%
  • Veröffentlicht 08.10.2026 08:18:19
  • Zuletzt bearbeitet 08.10.2026 21:18:01

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upst...

  • EPSS 0.19%
  • Veröffentlicht 08.10.2026 08:16:38
  • Zuletzt bearbeitet 08.10.2026 21:18:01

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints check permissi...

  • EPSS 0.23%
  • Veröffentlicht 29.09.2026 14:17:21
  • Zuletzt bearbeitet 29.09.2026 16:17:11

An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow t...

  • EPSS 0.35%
  • Veröffentlicht 29.09.2026 14:17:21
  • Zuletzt bearbeitet 29.09.2026 16:17:11

An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafte...

  • EPSS 0.15%
  • Veröffentlicht 29.09.2026 14:17:21
  • Zuletzt bearbeitet 01.10.2026 16:17:50

A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticate...

  • EPSS 0.18%
  • Veröffentlicht 29.09.2026 14:17:21
  • Zuletzt bearbeitet 29.09.2026 16:17:09

An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. T...