AI analysis
Apache DolphinScheduler before 3.4.3 has an authorization bypass (CWE-863) on task-instance stop and savepoint APIs. An authenticated user can call /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop or the matching savepoint endpoint for a project they are not allowed to access and still operate that task instance. The impact is unauthorized control of other projects’ running tasks, including stopping them or triggering a savepoint, which can disrupt scheduled data workflows. Any organization running an affected DolphinScheduler release is in scope; the issue is fixed in 3.4.3. There is no known public proof-of-concept and no report of in-the-wild exploitation, and the flaw is not listed in CISA KEV.
What to do: Upgrade Apache DolphinScheduler to version 3.4.3 or later. Until then, restrict access to the DolphinScheduler API to trusted networks and review logs for stop or savepoint calls against task instances in projects the caller should not control.
Affected
| Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
moderatethousands of self-hosted clusters (enterprise deployments, not a mass consumer product) — DolphinScheduler is a widely used open-source workflow scheduler deployed mainly as internal enterprise data-platform clusters; no public scan count or install total is in the CVE data, so this is an order-of-magnitude deployment-pattern…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.