Impact
Apache DolphinScheduler suffers from an authorization bypass that allows any authenticated user to call the /dolphinscheduler/users/list-all endpoint and view account data belonging to other users. The missing permission check exposes usernames, email addresses, and role information, enabling administrator or user enumeration and providing a foothold for further attacks. This weakness is identified as missing authorization checks (CWE-863).
Affected Systems
Apache DolphinScheduler versions before 3.4.3 are affected. Users of the Apache Software Foundation’s DolphinScheduler product should confirm that they are running version 3.4.3 or later to include the fix.
Risk and Exploitability
The EPSS score for this vulnerability is not available, and it is not listed in the CISA KEV catalog, indicating no known public exploitation. However, once an attacker has valid credentials, the flaw can be exploited simply by accessing the exposed endpoint, making the attack trivial for authenticated users. The impact is confined to confidentiality leakage of account information, and no additional conditions or advanced techniques are required.
OpenCVE Enrichment