PT-2024-12938 · Apache · Apache Doris

Andrea Cosentino

·

Published

2024-03-10

·

Updated

2024-08-05

·

CVE-2023-41313

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Doris versions prior to 2.0.0 Apache Doris version 1.2.8 and earlier
Description The authentication method in Apache Doris was vulnerable to timing attacks. This issue allows attackers to potentially exploit the system. Users are recommended to upgrade to a fixed version to resolve this issue.
Recommendations For Apache Doris versions prior to 2.0.0, upgrade to version 2.0.0 or later. For Apache Doris version 1.2.8 and earlier, upgrade to version 1.2.8 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-41313

Affected Products

Apache Doris