Apache

Doris

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.9%
  • Veröffentlicht 18.12.2023 09:15:05
  • Zuletzt bearbeitet 21.11.2024 08:21:03

The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.

  • EPSS 3.32%
  • Veröffentlicht 26.04.2022 16:15:47
  • Zuletzt bearbeitet 21.11.2024 06:49:29

Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.