Doris
Apache · 7 CVEs
CVE-2026-58319
CRITICAL
Apache Doris: Improper Authentication in Frontend HTTP API
Jul 14, 2026
CVE-2024-48019
MEDIUM
Apache Doris: allows admin users to read arbitrary files through the REST API
Feb 4, 2025
CVE-2024-27438
CRITICAL
Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution
Mar 21, 2024
CVE-2024-26307
MEDIUM
Apache Doris: Possible race condition
Mar 21, 2024
CVE-2023-41313
CRITICAL
Apache Doris: Timing Attack weakness
Mar 12, 2024
CVE-2023-41314
HIGH
Apache Doris: Missing API authentication allowed DoS
Dec 18, 2023
CVE-2022-23942
HIGH
Apache Doris hardcoded cryptography initialization
Apr 26, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-58319 | Apache Doris: Improper Authentication in Frontend HTTP API | CRITICAL | 0.75% | Jul 14, 2026 |
| CVE-2024-48019 | Apache Doris: allows admin users to read arbitrary files through the REST API | MEDIUM | 1.04% | Feb 4, 2025 |
| CVE-2024-27438 | Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution | CRITICAL | 0.96% | Mar 21, 2024 |
| CVE-2024-26307 | Apache Doris: Possible race condition | MEDIUM | 0.22% | Mar 21, 2024 |
| CVE-2023-41313 | Apache Doris: Timing Attack weakness | CRITICAL | 1.05% | Mar 12, 2024 |
| CVE-2023-41314 | Apache Doris: Missing API authentication allowed DoS | HIGH | 0.90% | Dec 18, 2023 |
| CVE-2022-23942 | Apache Doris hardcoded cryptography initialization | HIGH | 3.45% | Apr 26, 2022 |
Showing 1 to 7 of 7 CVEs