Impact
The vulnerability allows any ordinary user to create administrative access tokens by calling the /access-tokens endpoint. Because the issued token grants full control over the DolphinScheduler system, an attacker who can reach this endpoint can gain unrestricted administrative authority over the platform, endangering all stored data, configurations, and scheduled workflows.
Affected Systems
Apache DolphinScheduler versions prior to 3.4.2 are affected. The vulnerability is limited to this product and does not affect other Apache components.
Risk and Exploitability
The exploit requires reaching the /access-tokens endpoint, which is exposed to authenticated users; based upon the description it is inferred that any authenticated user can invoke this endpoint. If public access is permitted, the vulnerability could be exploited without authentication, though the data does not confirm this. The EPSS score is not available and the vulnerability is not listed in the KEV catalog; nevertheless the CVSS score of 8.8 reflects a high severity assessment. In a vulnerable deployment, an attacker who can invoke this endpoint may acquire an administrative access token and gain full control of the system.
OpenCVE Enrichment