Impact
An attacker who sends a request with a percent-encoded path can bypass the authentication checks that protect Actuator endpoints. The vulnerability stems from the way the application matches incoming request paths against protected endpoints, allowing the security logic to miss requests that are encoded. This flaw is a classic example of the improper use of path handling identified as CWE-863. When bypassed, the attacker can access management functions or view operational configuration that are normally restricted to authenticated users. The impact is the potential disclosure of sensitive data or unauthorized control of application behavior.
Affected Systems
The flaw affects Apache DolphinScheduler installations running any version prior to 3.4.3. The affected vendor is the Apache Software Foundation. If your deployment uses an older release, it is susceptible to this bypass. All other versions are unaffected.
Risk and Exploitability
Because the vulnerability does not require additional privileges or local access, a remote, unauthenticated attacker can exploit it over the network by crafting a single HTTP request. No EPSS score is available, but the nature of the bug – an unchecked authentication bypass – indicates a high likelihood of exploitation in environments where Actuator endpoints are left enabled and reachable. The flaw is not yet listed in the CISA KEV catalog, yet the risk remains significant due to the potential for information disclosure or misuse of management features.
OpenCVE Enrichment