AI analysis
Apache DolphinScheduler versions from 3.2.0 before 3.4.3 have a missing authorization flaw (CWE-863) in the query-dynamic-sub-workflows API. An authenticated user who lacks access to a given project can call the API with parameters that reference that project’s workflows and receive workflow information they are not allowed to see. The result is unauthorized disclosure of workflow data across project boundaries, not remote code execution. Organizations running affected DolphinScheduler releases are impacted. There is no known public proof of concept and the issue is not listed in CISA KEV.
What to do: Upgrade Apache DolphinScheduler to 3.4.3 or later, which fixes the missing authorization check. Until then, restrict access to the query-dynamic-sub-workflows API (network controls and least-privilege project roles) and review API logs for authenticated users querying workflow IDs outside their assigned projects.
Affected
| Apache DolphinScheduler | 3.2.0 before 3.4.3 |
Estimated exposure
moderatelow thousands to tens of thousands of deployments — Apache DolphinScheduler is a widely used open-source workflow scheduler, typically self-hosted inside data platforms rather than exposed as a public internet service; there is no public install census, so the figure is an…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can invoke the API with parameters referencing workflows belonging to that project and retrieve workflow information. This allows users to access workflow data outside their authorized project scope, resulting in unauthorized information disclosure. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.