PT-2025-2787 · Apache · Apache Doris
Man Yue Mo
·
Published
2025-02-04
·
Updated
2025-02-07
·
CVE-2024-48019
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Doris versions prior to 2.1.8
Apache Doris versions prior to 3.0.3
Description:
The issue allows application administrators to read arbitrary files from the server filesystem through path traversal, which is a type of vulnerability known as Improper Limitation of a Pathname to a Restricted Directory. This can be exploited through the REST API.
Recommendations:
For Apache Doris versions prior to 2.1.8, upgrade to version 2.1.8 or later to fix the issue.
For Apache Doris versions prior to 3.0.3, upgrade to version 3.0.3 or later to fix the issue.
As a temporary workaround, consider restricting access to the REST API to minimize the risk of exploitation.
Fix
Path traversal
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Doris