CVE-2026-71895
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
08/10/2026
Última modificación:
08/10/2026
Descripción
*** Pendiente de traducción *** An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler.<br />
<br />
<br />
<br />
The impact depends on the permissions granted to the disclosed credentials. If the kubeconfig provides cluster-admin or broadly privileged service-account access, an attacker may read Kubernetes Secrets, create pods, and establish persistent access to the cluster.<br />
<br />
<br />
<br />
This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3.<br />
<br />
<br />
<br />
Users are recommended to upgrade to version 3.4.3, which fixes the issue.


