Impact
Apache DolphinScheduler contains an improper authorization check that allows an authenticated user to invoke the batch‑copy and batch‑move endpoints and operate on workflows in projects for which they lack the required permissions. The flaw is an example of CWE‑863, where the system fails to enforce proper access control, enabling the user to copy or move workflows from unauthorized projects. This can lead to privilege escalation and unauthorized data exposure within the scheduler environment.
Affected Systems
All users of the Apache Software Foundation’s Apache DolphinScheduler, specifically installations running any version prior to 3.4.3. The vulnerability applies to the batch‑copy and batch‑move features accessible by authenticated accounts.
Risk and Exploitability
The issue requires the attacker to be authenticated and to have some baseline permissions within DolphinScheduler, but the flaw permits extrapolation of privileges to other projects. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, implying that no public exploit is known at this time. Nevertheless, the CVSS score is not provided, so the precise severity cannot be quantified here; the potential for unauthorized workflow manipulation remains significant.
OpenCVE Enrichment