Impact
The vulnerability allows an authenticated user to reference and run a sub‑workflow belonging to a project they do not have permission to access. This bypasses project‑level authorization controls, enabling the attacker to trigger workflow execution in unauthorized projects and potentially expose resources or data managed by those workflows.
Affected Systems
Apache DolphinScheduler installations running any version prior to 3.4.3 are affected. The flaw resides in the component that validates sub‑workflow tasks within the scheduler.
Risk and Exploitability
The CVSS score is not publicly disclosed, but the flaw is a classic improper authorization that effectively gives an authenticated user full execution rights in another project. Since the attacker only needs to be logged in, the attack could be carried out remotely through standard UI or API calls. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating that while the exploitation probability may not be considered high, the impact of successful exploitation is significant and warrants prompt remediation.
OpenCVE Enrichment