CVE Database
/

CVE-2025-58337

Back to search

CVE-2025-58337

Published: Nov 5, 2025

Modified: Nov 6, 2025

PUBLISHED

Description

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions. Impact: Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications. Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).

VendorProductVersions

Apache Software Foundation

Apache Doris-MCP-Server

affected
0.1.0 - < 0.6.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now