CRITICAL
Apache Doris: Timing Attack weakness
Published Mar 12, 2024
9.8
CRITICALCVSS 3.1
EPSS 1.05%
Description
The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.
Affected products
-
Affected
- ≥ 0, < 1.2.8
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Doris | unaffected | Affected
|
-
Affected
- ≥ 0, < 1.2.8
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.openwall.com/lists/oss-security/2024/03/10/2 Mailing List
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-45829 Advisory
- https://lists.apache.org/thread/jqczy3vxzs6q6rz9o0626j5nks9fnv95 vendor-advisoryMailing ListVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2024/03/10/2 | Mailing List | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-45829 | Advisory | |
| https://lists.apache.org/thread/jqczy3vxzs6q6rz9o0626j5nks9fnv95 | vendor-advisoryMailing ListVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Mar 12, 2024
Updated Feb 13, 2025
Reserved Aug 28, 2023
Link CVE-2023-41313
CISA Vulnrichment
Updated Aug 5, 2024
Red Hat
No data
GitHub
No data