PT-2026-102616 · Apache · Dolphinscheduler
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache DolphinScheduler versions prior to 3.4.3
Description
An improper authorization issue exists in the handling of sub-workflow tasks. An authenticated user without permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system fails to properly verify if the user has permission to execute the referenced workflow or access its project, allowing the bypass of project-level authorization controls. This may lead to the unauthorized execution of workflow tasks and access to resources or data available to the target workflow.
Recommendations
Upgrade to version 3.4.3.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dolphinscheduler