Apache doris是美国Apache基金会开源的一款实时分析数据库。 Apache Doris 3.1.0之前版本存在授权问题漏洞,该漏洞源于FE HTTP REST管理API缺乏适当身份验证,可能导致未经验证的攻击者通过网络访问执行未授权管理操作,影响集群完整性和可用性,导致集群不稳定或拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Doris | 2.1.0< 3.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Doris | 2.1.0 ~ 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49488 | Apache OpenMeetings: Arbitrary File Read | |
| CVE-2026-62393 | Apache Kylin: Improper authorization in job information retrieval | |
| CVE-2026-62392 | Apache Kylin: OS Command Injection via Async Query API | |
| CVE-2026-62390 | Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API | |
| CVE-2026-59084 | Apache Tomcat: EncryptInterceptor requirements not clearly documented | |
| CVE-2026-59083 | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass |
No comments yet