Description
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version before 3.4.2
Credits
thesecguy45@gmail.com
udolemi (S2W)
References
www.openwall.com/lists/oss-security/2026/06/17/5
lists.apache.org/thread/gx6v1wjb6qg3fzksxomysspy2gw54ooc