Medium severity5.4NVD Advisory· Published Feb 4, 2025· Updated Jun 17, 2026
CVE-2024-48019
CVE-2024-48019
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris.
Application administrators can read arbitrary files from the server filesystem through path traversal.
Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.
Affected products
3- Apache Software Foundation/Apache Dorisv5Range: 2.1.0
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2025/02/04/2nvdMailing ListVendor Advisory
- lists.apache.org/thread/p70klgmyrgknhn0t195261wvwv5jw6hrnvdVendor Advisory
News mentions
0No linked articles in our index yet.