Vulnerability Description
The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Doris | < 2.0.3 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/tgvpvz3yw7zgodl1sb3sv3jbbz8t5zb4Mailing ListVendor Advisory
- https://lists.apache.org/thread/tgvpvz3yw7zgodl1sb3sv3jbbz8t5zb4Mailing ListVendor Advisory
FAQ
What is CVE-2023-41314?
CVE-2023-41314 is a vulnerability with a CVSS score of 8.2 (HIGH). The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.
How severe is CVE-2023-41314?
CVE-2023-41314 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41314?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Doris.