Impact
An Apache DolphinScheduler vulnerability allows authenticated users to bypass project authorization and alter task definitions and their upstream dependencies via the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint does not verify that the referenced task belongs to the specified project, enabling a user to supply a task code from a different project and change its configuration. This breach can compromise workflow integrity and disrupt execution of tasks in projects where the user has no legitimate access.
Affected Systems
All installations of Apache DolphinScheduler prior to version 3.4.3 are affected. The vulnerability applies to the core project authorization logic of the DolphinScheduler platform.
Risk and Exploitability
While no CVSS or EPSS score is published, the flaw represents a high severity privilege escalation (CWE‑863). An attacker only needs an authenticated account to craft the request, meaning the attack surface is wide for users who have any login credentials. Because the flaw directly modifies configuration data, the potential for workflow disruption is significant, yet no exploitation evidence or KEV listing is currently available. The absence of an EPSS score suggests limited public exploitation at this time, but the capability remains.
OpenCVE Enrichment