Impact
A missing authorization check in the query-dynamic-sub-workflows API allows any authenticated user to request workflow data belonging to projects for which they do not have permission. The result is that users can obtain detailed workflow information outside their authorized project scope, exposing sensitive operational data. The vulnerability is a classic example of improper access control for data retrieval, classified as CWE‑863.
Affected Systems
Apache DolphinScheduler versions from 3.2.0 up to but not including 3.4.3 are affected. The issue does not apply to earlier releases or to 3.4.3 and later, which contain the fix.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, yet the attack vector is clear: an authenticated user who lacks project‑level permissions can invoke the API with workflow identifiers from other projects and retrieve the data. This is an easier exploit path than traditional remote code execution; it requires only that the attacker can authenticate to the system and knows or can guess workflow IDs. The risk is tied to the breadth of user accounts and the sensitivity of workflow definitions. Organizations with large numbers of users or highly confidential projects may consider the risk moderate to high, even without an exact EPSS score.
OpenCVE Enrichment