VendorsApachedorisany version
Vulnerabilities

Apache Doris any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-41313
Apache Doris: Timing Attack weakness
Published 2024-03-12 · Analyzed
9.8EPSS 0.010
CVE-2024-27438
Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution
Published 2024-03-21 · Analyzed
9.8EPSS 0.010
CVE-2026-58319
Apache Doris: Improper Authentication in Frontend HTTP API
Published 2026-07-14 · Analyzed
9.1EPSS 0.007
CVE-2023-41314
Apache Doris: Missing API authentication allowed DoS
Published 2023-12-18 · Modified
8.2EPSS 0.009
CVE-2022-23942
Apache Doris hardcoded cryptography initialization
Published 2022-04-26 · Modified
7.5EPSS 0.035
CVE-2024-48019
Apache Doris: allows admin users to read arbitrary files through the REST API
Published 2025-02-04 · Analyzed
5.4EPSS 0.010
CVE-2024-26307
Apache Doris: Possible race condition
Published 2024-03-21 · Analyzed
5.3EPSS 0.002