AI analysis
Apache DolphinScheduler before 3.4.3 has an incorrect-authorization flaw (CWE-863) in several project APIs. Authenticated users who already have the needed rights in one project can send that project's projectCode together with a schedule, workflow-definition, or task-instance identifier from a different project, because the endpoints check permission only against the supplied project code and do not confirm the resource belongs to it. That lets them turn schedules on or off and change workflow definitions between ONLINE and OFFLINE in projects they are not allowed to access, disrupting workflow availability and task execution. Only deployments running versions before 3.4.3 are affected, and the fix is in 3.4.3. There is no known public proof of concept and no report of exploitation in the wild.
What to do: Upgrade Apache DolphinScheduler to 3.4.3 or later. Until then, restrict who can call schedule online/offline and workflow-definition release APIs, and review recent cross-project schedule and workflow state changes for unauthorized ONLINE/OFFLINE actions.
Affected
| Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
moderatelow thousands to tens of thousands of self-hosted deployments — DolphinScheduler is a self-hosted Apache data-workflow scheduler used mainly inside enterprises; there is no public install or internet-scan count in this data, so the figure is an order-of-magnitude estimate of typical deployments rather…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints check permissions against the supplied projectCode but fail to verify that the target resource belongs to that project. An authenticated user with the required permissions in one project can supply that project's code together with a resource identifier from another project, bypassing the target project's access restrictions. The affected endpoints include: * POST /projects/{projectCode}/schedules/{id}/online and /offline: Activate or deactivate workflow schedules in another project. * POST /projects/{projectCode}/workflow-definition/{code}/release: Change the ONLINE/OFFLINE state of workflow definitions in another project. Successful exploitation allows users to alter workflow availability and interfere with task execution in projects they are not authorized to access. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.