Apache Doris是美国阿帕奇(Apache)基金会的一个现代 MPP 分析数据库产品。可以提供亚秒级查询和高效的实时数据分析。 Apache Doris 1.2.8之前版本,2.0.4之前版本存在竞争条件问题漏洞,该漏洞源于使用了chmod()函数,导致攻击者可以从user下重命名文件并对文件进行修改权限操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Doris | 0 ~ 1.2.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-27438 | Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution | |
| CVE-2024-29131 | Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterH | |
| CVE-2024-29133 | Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Obje |
No comments yet