Apache

Dolphinscheduler

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 29.09.2026 14:17:20
  • Zuletzt bearbeitet 29.09.2026 16:17:09

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy o...

  • EPSS 0.5%
  • Veröffentlicht 29.09.2026 13:17:52
  • Zuletzt bearbeitet 29.09.2026 21:19:33

The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource w...

  • EPSS 0.23%
  • Veröffentlicht 29.09.2026 12:17:10
  • Zuletzt bearbeitet 06.10.2026 14:37:36

The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source co...

  • EPSS 0.23%
  • Veröffentlicht 24.09.2026 09:13:45
  • Zuletzt bearbeitet 24.09.2026 19:36:39

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. Thi...

  • EPSS 0.28%
  • Veröffentlicht 25.08.2026 09:57:48
  • Zuletzt bearbeitet 28.09.2026 23:10:00

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

  • EPSS 0.43%
  • Veröffentlicht 17.06.2026 09:00:12
  • Zuletzt bearbeitet 17.06.2026 09:00:12

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to versio...

  • EPSS 0.34%
  • Veröffentlicht 17.06.2026 08:57:55
  • Zuletzt bearbeitet 17.06.2026 08:57:55

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

  • EPSS 0.31%
  • Veröffentlicht 17.06.2026 08:56:55
  • Zuletzt bearbeitet 17.06.2026 08:56:55

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to up...

  • EPSS 0.44%
  • Veröffentlicht 17.06.2026 08:55:29
  • Zuletzt bearbeitet 17.06.2026 08:55:29

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4...

  • EPSS 0.39%
  • Veröffentlicht 17.06.2026 08:43:11
  • Zuletzt bearbeitet 17.06.2026 08:43:11

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the i...