CVE-2026-66083 Apache DolphinScheduler 授权绕过漏洞
影响已认证用户可越权读取未授权数据源的配置等敏感信息
Apache DolphinScheduler 的 /datasources/unauth-datasource 接口未正确校验数据源授权。已认证的普通用户可调用该接口,获取其本无权访问的数据源信息,导致数据源配置及元数据泄露。
影响范围
Apache DolphinScheduler 3.4.3 之前的版本。
漏洞详情
该漏洞属于越权访问/授权缺失类问题。接口在返回数据源信息时未校验当前用户是否对该数据源拥有访问权限,任何已登录用户均可通过构造请求读取他人数据源的配置与元数据。具体泄露字段取决于接口返回内容。
利用条件与风险
利用前提是攻击者拥有一个有效登录账号,无需高权限;实战中可用于信息收集,为后续横向渗透提供凭据或连接信息,风险中等。
修复建议
官方建议升级至 3.4.3 版本修复该问题;在升级前可限制该接口的访问权限或对数据源访问进行额外鉴权。
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.