VYPR
Medium severity5.4NVD Advisory· Published Feb 4, 2025· Updated Jun 17, 2026

CVE-2024-48019

CVE-2024-48019

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris.

Application administrators can read arbitrary files from the server filesystem through path traversal.

Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.

Affected products

3
  • Apache/Doris2 versions
    cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*range: >=2.1.0,<2.1.8
    • (no CPE)range: up to 2.1.8, 3.0.3
  • Apache Software Foundation/Apache Dorisv5
    Range: 2.1.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.