📦 Doris

by Apache

🔍 What is Doris?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-27438

CRITICAL CVSS 9.8 Mar 21, 2024

This vulnerability in Apache Doris allows authenticated users with JDBC catalog creation privileges to upload and execute arbitrary Java code via malicious JDBC driver files. Attackers can achieve rem...

CVE-2022-23942

HIGH CVSS 7.5 Apr 26, 2022

CVE-2022-23942 is a vulnerability in Apache Doris where hardcoded cryptographic keys and initialization vectors (IVs) were used for encrypting LDAP passwords. This allows attackers to decrypt stored L...

CVE-2024-48019

MEDIUM CVSS 5.4 Feb 4, 2025

This path traversal vulnerability in Apache Doris allows authenticated application administrators to read arbitrary files from the server filesystem. Attackers can exploit this to access sensitive sys...