AI analysis
Apache DolphinScheduler before 3.4.3 has an incorrect-authorization flaw (CWE-863) in the task-definition with-upstream API. An authenticated user can supply a project code they are allowed to access together with a task-definition code from a different project, because the endpoint does not verify that the task belongs to the stated project. That lets the user modify the target task definition and its upstream dependencies, compromising workflow integrity and disrupting execution in projects they should not access. Every DolphinScheduler release before 3.4.3 is affected. No public proof of concept is known, the issue is not in CISA KEV, and CVSS has not yet been scored.
What to do: Upgrade Apache DolphinScheduler to 3.4.3 or later. Until the upgrade is in place, restrict who can authenticate to the scheduler API and do not expose the service to the public internet. Review task-definition and upstream-dependency change history for edits by users who were not authorized for the affected project.
Affected
| Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
moderatelow thousands to about 10,000 deployments (order-of-magnitude estimate) — DolphinScheduler is a widely used Apache workflow scheduler deployed mainly inside enterprises rather than as a mass consumer product; the advisory gives no active-install count or public internet-scan figure, so the range is an…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.