Impact
This flaw allows an authenticated user to perform actions on schedules, workflow definitions, and task instances that belong to a different project by supplying the target project code along with a resource identifier from that other project. The core issue is that the API checks the supplied projectCode but does not confirm that the target resource actually resides in that project. As a result, an attacker can activate or deactivate schedules, release or retire workflow definitions, and otherwise manipulate the availability and execution behavior of workflows that the attacker is not authorized to view or manage. The change enables an attacker to interfere with or sabotage task execution across projects, potentially causing loss of availability and compromising operational integrity.
Affected Systems
Apache DolphinScheduler versions prior to 3.4.3 are impacted. Users running the open‑source scheduler from the Apache Software Foundation should verify whether they are running a version older than 3.4.3 and, if so, plan an upgrade.
Risk and Exploitability
The flaw is exploitable through the public REST endpoints once the attacker has a valid authenticated session. The attack vector is internal to the application, requiring legitimate credentials, but not requiring elevated privileges beyond those granted within a single project. While the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, the capabilities provided—unauthorized schedule activation, deactivation, and workflow definition release—constitute a high‑impact manipulation of critical workflow orchestrations. The absence of a public exploit report does not diminish the risk, as the vulnerability can be exercised by any authenticated user with access to any project.
OpenCVE Enrichment