VYPR
Unrated severityNVD Advisory· Published Feb 4, 2025· Updated Feb 7, 2025

Apache Doris: allows admin users to read arbitrary files through the REST API

CVE-2024-48019

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris.

Application administrators can read arbitrary files from the server filesystem through path traversal.

Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.

Affected products

2
  • Apache/Dorisllm-create
    Range: <=2.1.7, <=3.0.2
  • Apache Software Foundation/Apache Dorisv5
    Range: 2.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.