CVE-2024-27438

CRITICAL

Apache Doris 1.2.0-2.0.4 - Remote Code Execution via Unchecked JDBC Driver File

Title source: llm
STIX 2.1

Description

Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. Once the attacker is authorized to create a JDBC catalog, he/she can use arbitrary driver jar file with unchecked code snippet. This code snippet will be run when catalog is initializing without any check. This issue affects Apache Doris: from 1.2.0 through 2.0.4. Users are recommended to upgrade to version 2.0.5 or 2.1.x, which fixes the issue.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0096
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-494
Status published
Products (1)
apache/doris 1.2.0 - 2.0.5
Published Mar 21, 2024
Tracked Since Feb 18, 2026