CVE-2026-78214 Apache DolphinScheduler Actuator 认证绕过漏洞
影响未授权攻击者可绕过认证访问受保护的 Actuator 端点,泄露敏感信息
Apache DolphinScheduler 在保护 Actuator 端点时存在认证绕过漏洞。应用通过将请求路径与受保护的 Actuator 路径进行匹配来判断是否需要认证,攻击者可通过发送包含百分号编码路径的特制请求使安全检查失效。该漏洞影响 3.4.3 之前的版本。
影响范围
Apache DolphinScheduler 3.4.3 之前的版本。
漏洞详情
漏洞类型为认证绕过(路径匹配缺陷)。成因是安全校验依赖对请求路径的字符串匹配,而未对百分号编码等变形路径进行规范化处理,导致校验逻辑无法识别请求实际指向受保护的 Actuator 端点。远程未认证攻击者可构造含编码路径的请求绕过认证,访问本应受限的 Actuator 端点,从而获取运行或配置信息,并可能触及敏感管理功能。
利用条件与风险
利用无需认证,攻击者仅需发送特制请求即可尝试绕过,实战中可能导致敏感配置与运行信息泄露,风险取决于已启用的 Actuator 端点及配置。
修复建议
官方建议升级至 3.4.3 版本以修复该问题;在无法立即升级时,可限制 Actuator 端点的网络访问或禁用不必要的端点作为临时缓解措施。
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated attacker can cause the security check to fail to recognize the request as targeting a protected endpoint.
As a result, the attacker may bypass authentication and access otherwise restricted Actuator endpoints. Successful exploitation may expose operational or configuration information and, depending on the enabled endpoints and application configuration, allow access to sensitive management functionality.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.