All 5 CVE vulnerabilities found in Apache Doris, with AI-generated Chinese analysis, references, and POCs.
Vendor: Apache Software Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-48019 | Apache Doris: allows admin users to read arbitrary files through the REST API CWE-22 | 4.9 | - | 2025-02-04 |
| CVE-2024-27438 | Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution CWE-494 | 8.8AI | HighAI | 2024-03-21 |
| CVE-2024-26307 | Apache Doris: Possible race condition CWE-362 | 6.5AI | MediumAI | 2024-03-21 |
| CVE-2023-41313 | Apache Doris: Timing Attack weakness CWE-208 | 5.9AI | MediumAI | 2024-03-12 |
| CVE-2023-41314 | Apache Doris: Missing API authentication allowed DoS CWE-863 | 9.1AI | CriticalAI | 2023-12-18 |
All 5 known CVE vulnerabilities affecting Apache Doris with full Chinese analysis, references, and POCs where available.