Skip to content

Sensitive Data: Apache DolphinScheduler Default Login

Identifier: dolphinscheduler_default_login

Scanner(s) Support

GraphQL Scanner REST Scanner WebApp Scanner ASM Scanner

Description

Apache DolphinScheduler workflow orchestration platform may be accessible with default admin credentials, allowing unauthorized access to workflow definitions, job scheduling, and administrative functions.

How we test: We attempt to authenticate to the Apache DolphinScheduler web interface using common default username and password combinations. If authentication succeeds, we report the vulnerability.

Reference:

Configuration

Example

Example configuration:

---
security_tests:
  dolphinscheduler_default_login:
    skip: false

Reference

skip

Type : boolean

Skip the test if true.