Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-27438

Опубликовано: 21 мар. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. Once the attacker is authorized to create a JDBC catalog, he/she can use arbitrary driver jar file with unchecked code snippet. This code snippet will be run when catalog is initializing without any check. This issue affects Apache Doris: from 1.2.0 through 2.0.4.

Users are recommended to upgrade to version 2.0.5 or 2.1.x, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*
Версия от 1.2.0 (включая) до 2.0.5 (исключая)

EPSS

Процентиль: 87%
0.03445
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 9.8
github
почти 2 года назад

Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. Once the attacker is authorized to create a JDBC catalog, he/she can use arbitrary driver jar file with unchecked code snippet. This code snippet will be run when catalog is initializing without any check. This issue affects Apache Doris: from 1.2.0 through 2.0.4. Users are recommended to upgrade to version 2.0.5 or 2.1.x, which fixes the issue.

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость Backend-хранилища и Frontend-обработчика запросов Apache Doris, связанная с загрузкой кода без проверки его целостности, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 87%
0.03445
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494