Back

MEDIUM

Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource

Published Sep 29, 2026

Description

The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint.

This issue affects Apache DolphinScheduler: before 3.4.3.

Users are recommended to upgrade to version 3.4.3, which fixes the issue.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Jul 24, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Analyzed
Modified Oct 6, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Sep 29, 2026
Updated Sep 29, 2026
Exploited since n/a
EUVD-2026-88742