Database/Control plane, storage & DevOps
Apache DolphinScheduler: exposed management endpoints leak database credentials to unauthenticated callers
Impact
DolphinScheduler 3.1.x leaves its Spring Boot management endpoints broadly exposed, so an unauthenticated caller who can reach the service reads back sensitive configuration including database credentials. Where DolphinScheduler drives data and training pipelines on a fleet, its metadata database holds the pipeline definitions and connection details for everything it orchestrates - the credentials recovered this way typically open object storage, warehouses and job submission paths well beyond the scheduler itself. Impact is confidentiality only; nothing here grants code execution directly. NVD notes this is the same issue previously tracked as CVE-2023-48796.
Who can reach it
Anyone who can reach the DolphinScheduler API/management port. No authentication required. Not exploitable if the service is bound to a trusted network only - but the endpoints are open to anyone who gets that far.
What to do
Upgrade to 3.2.0 or later. If an upgrade window is not available, restrict the exposed endpoints with MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus or the equivalent management.endpoints.web.exposure.include block in application.yaml, which the Apache advisory gives as the temporary workaround. Either path is a service restart of the DolphinScheduler components, not a node action; running jobs are affected only as far as a scheduler restart affects them. Rotate any database credentials that were readable while the endpoints were exposed.
References
Related entries
- IBM Storage Scale GUI (hardcoded inter-node token): A hardcoded token in the Storage Scale GUI source, usedCVE-2026-13460 · IBM Storage Scale GUI (hardcoded inter-node token)High
- Performance Co-Pilot: signed integer overflow in __pmGetPDU permanently blinds the collector daemonCVE-2026-16529 · Performance Co-Pilot pmcd/PMAPI (__pmGetPDU PDU length handling)High
- Automated Logic WebCTRL / i-Vu server and controllers, BACnet transport trust: This is the vendor formally concedingCVE-2026-32666 · Automated Logic WebCTRL / i-Vu server and controllers, BACnet transport trustHigh
- Apache Tomcat: Missing encryption of sensitive data introduced by the CVE-2026-29146 fixCVE-2026-34486 · Apache TomcatHigh
- JFrog Artifactory: internal anonymous-user token returned to unauthenticated callersCVE-2026-42018 · JFrog Artifactory (anonymous-user token disclosure)High
- Prometheus: Azure AD remote-write client secret served in plaintext from the /-/config endpointCVE-2026-42151 · Prometheus (Azure AD remote-write OAuth client_secret in /-/config)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.