AI analysis
Apache DolphinScheduler before 3.4.3 has an incorrect authorization check (CWE-863) on PUT /projects/{projectCode}/workflow-instances/{id}. An authenticated user who has only read permission on a project can call that endpoint and modify a workflow instance, because the handler does not require the write permission this operation needs. The result is unauthorized changes to workflow instances by accounts that should be limited to read access. Any installation of Apache DolphinScheduler older than 3.4.3 is affected. No public proof of concept is known and the issue is not in CISA KEV, so exploitation is none known.
What to do: Upgrade Apache DolphinScheduler to 3.4.3 or later, which enforces the required write permission on this endpoint. Until then, do not grant project access to users who must not change workflows, and review workflow-instance history for unexpected edits by read-only accounts.
Affected
| Apache DolphinScheduler | before 3.4.3 |
Estimated exposure
moderateon the order of 1,000–10,000 enterprise deployments (not mass consumer installs) — No active-install or internet-scan count is in the CVE data; the estimate is from DolphinScheduler’s typical use as an enterprise, often internal, open-source data workflow scheduler rather than a mass public web app.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this operation, allowing the user to make unauthorized changes to workflow instances. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.