Back

CRITICAL

Apache Doris: Timing Attack weakness

Published Mar 12, 2024

Description

The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Mar 12, 2024
Updated Feb 13, 2025
Reserved Aug 28, 2023

CISA Vulnrichment

Updated Aug 5, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner apache
Published Mar 12, 2024
Updated Feb 13, 2025

GitHub

No data