AI analysis
Apache DolphinScheduler before 3.4.3 has an incorrect authorization check (CWE-863) on its batch-copy and batch-move workflow endpoints. An already authenticated user can call those endpoints to copy or move workflows that belong to projects they are not permitted to access. Impact is unauthorized workflow relocation or duplication across projects, not unauthenticated remote code execution. Only deployments running a release older than 3.4.3 are affected. The issue is not listed in CISA KEV, has no known public proof-of-concept, and is not known to be exploited in the wild; CVSS has not yet been scored.
What to do: Upgrade Apache DolphinScheduler to 3.4.3 or later. Until then, restrict which authenticated users can reach the batch-copy and batch-move workflow APIs, and review audit logs for copies or moves of workflows across projects the actor was not permitted to access.
Affected
| Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.