Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-57pr-424c-2xfr

Опубликовано: 21 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Possible race condition vulnerability in Apache Doris. Some of code using chmod() method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4.

Users are recommended to upgrade to version 2.0.4, which fixes the issue.

Possible race condition vulnerability in Apache Doris. Some of code using chmod() method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4.

Users are recommended to upgrade to version 2.0.4, which fixes the issue.

EPSS

Процентиль: 8%
0.00029
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.3
nvd
почти 2 года назад

Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4. Users are recommended to upgrade to version 2.0.4, which fixes the issue.

CVSS3: 3.8
fstec
почти 2 года назад

Уязвимость метода chmod() Backend-хранилища и Frontend-обработчика запросов Apache Doris, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 8%
0.00029
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-362