Impact
The /datasources/unauth-datasource endpoint in Apache DolphinScheduler does not enforce proper data source authorization, allowing an authenticated user to retrieve configuration details and other metadata for data sources they should not have access to. This flaw, identified as CWE-306, results in a confidentiality breach that could expose credentials, connection strings, or other sensitive configuration information. The impact is limited to the data sources visible through this endpoint but could assist an attacker in further compromising systems that use those data sources.
Affected Systems
All installations of Apache DolphinScheduler prior to version 3.4.3 are vulnerable. Any environment running an affected version and providing this endpoint is at risk, regardless of the number of users or the network environment.
Risk and Exploitability
No CVSS score is available for this issue, and the EPSS score is not provided; it is not listed in the CISA KEV catalog. An attacker must first authenticate to the DolphinScheduler instance and then invoke the vulnerable endpoint. Because the flaw depends on possession of valid credentials, the primary attack vector is insider or compromised legitimate user access. While active exploitation has not been reported, the potential for data exposure makes this a moderate to high risk for organizations with sensitive data source configurations.
OpenCVE Enrichment