CVE-2026-71899 Apache DolphinScheduler 越权访问漏洞
影响认证用户可越权读取未授权项目的工作流信息
Apache DolphinScheduler 的 query-dynamic-sub-workflows API 存在缺失授权校验漏洞。该接口未正确验证已认证用户是否有权访问所查询的工作流,导致越权信息泄露。
影响范围
Apache DolphinScheduler 3.2.0 至 3.4.3 之前的版本。
漏洞详情
漏洞类型为缺失授权(越权访问)。成因是接口仅校验用户已登录,却未校验其对目标项目/工作流的访问权限。已认证但无对应项目权限的用户,可通过构造引用其他项目工作流的参数调用该 API,从而获取本无权查看的工作流信息。
利用条件与风险
利用前提是攻击者拥有一个有效账号(任意低权限用户即可)。实战中可导致跨项目的工作流配置等敏感信息泄露,属于信息泄露类风险。
修复建议
官方建议升级至 3.4.3 版本以修复该问题;暂无公开的临时缓解措施信息。
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried.
An authenticated user who does not have permission to access a specific project can invoke the API with parameters referencing workflows belonging to that project and retrieve workflow information. This allows users to access workflow data outside their authorized project scope, resulting in unauthorized information disclosure.
This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.