Impact
Unauthorized actors can retrieve sensitive data, such as database credentials, by accessing the actuator endpoint of Apache DolphinScheduler. The weakness is a confidential data exposure (CWE‑200) resulting in a breach of confidentiality for the system and potentially linked services.
Affected Systems
Apache DolphinScheduler produced by the Apache Software Foundation is affected. All releases in the 3.1.x series are vulnerable. Users should upgrade to version 3.2.0 or later to eliminate the exposure.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity, while the EPSS score below 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the exposed actuator endpoint, which lacks authentication checks. No additional prerequisites beyond reaching the endpoint are stated in the available information.
OpenCVE Enrichment
Github GHSA