CVE Database
/

CVE-2023-41314

Back to search

CVE-2023-41314

Published: Dec 18, 2023

Modified: Nov 20, 2024

PUBLISHED

Description

The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.

VendorProductVersions

Apache Software Foundation

Apache Doris

affected
1.2.0 - <= 2.0.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now