GPU VulnDB

Database/Control plane, storage & DevOps

Apache DolphinScheduler: exposed management endpoints leak database credentials to unauthenticated callers

CVSS 7.5CVE-2025-62188Control plane, storage & DevOpscurated

Impact

DolphinScheduler 3.1.x leaves its Spring Boot management endpoints broadly exposed, so an unauthenticated caller who can reach the service reads back sensitive configuration including database credentials. Where DolphinScheduler drives data and training pipelines on a fleet, its metadata database holds the pipeline definitions and connection details for everything it orchestrates - the credentials recovered this way typically open object storage, warehouses and job submission paths well beyond the scheduler itself. Impact is confidentiality only; nothing here grants code execution directly. NVD notes this is the same issue previously tracked as CVE-2023-48796.

Who can reach it

Anyone who can reach the DolphinScheduler API/management port. No authentication required. Not exploitable if the service is bound to a trusted network only - but the endpoints are open to anyone who gets that far.

What to do

Upgrade to 3.2.0 or later. If an upgrade window is not available, restrict the exposed endpoints with MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus or the equivalent management.endpoints.web.exposure.include block in application.yaml, which the Apache advisory gives as the temporary workaround. Either path is a service restart of the DolphinScheduler components, not a node action; running jobs are affected only as far as a scheduler restart affects them. Rotate any database credentials that were readable while the endpoints were exposed.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.