PT-2025-2787 · Apache · Apache Doris

Man Yue Mo

·

Published

2025-02-04

·

Updated

2025-02-07

·

CVE-2024-48019

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Apache Doris versions prior to 2.1.8 Apache Doris versions prior to 3.0.3
Description: The issue allows application administrators to read arbitrary files from the server filesystem through path traversal, which is a type of vulnerability known as Improper Limitation of a Pathname to a Restricted Directory. This can be exploited through the REST API.
Recommendations: For Apache Doris versions prior to 2.1.8, upgrade to version 2.1.8 or later to fix the issue. For Apache Doris versions prior to 3.0.3, upgrade to version 3.0.3 or later to fix the issue. As a temporary workaround, consider restricting access to the REST API to minimize the risk of exploitation.

Fix

Path traversal

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-48019

Affected Products

Apache Doris