PT-2026-97242 · Apache · Apache Doris
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Doris versions 2.0.0 through 2.0.x
Apache Doris versions 2.1.0 through 2.1.x
Apache Doris versions 3.0.0 through 3.0.x
Apache Doris versions 3.1.0 through 3.1.x
Apache Doris versions 4.0.0 through 4.0.7
Apache Doris versions 4.1.0 through 4.1.3
Description
An improper authentication issue in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints rely on client-supplied node information for authentication without sufficiently verifying the requesting party. In specific network configurations, this allows an attacker to bypass access controls and access internal FE metadata interfaces, which may expose sensitive cluster information.
Recommendations
Upgrade Apache Doris versions 2.0.0 through 2.0.x to version 4.0.8 or 4.1.4.
Upgrade Apache Doris versions 2.1.0 through 2.1.x to version 4.0.8 or 4.1.4.
Upgrade Apache Doris versions 3.0.0 through 3.0.x to version 4.0.8 or 4.1.4.
Upgrade Apache Doris versions 3.1.0 through 3.1.x to version 4.0.8 or 4.1.4.
Upgrade Apache Doris versions 4.0.0 through 4.0.7 to version 4.0.8.
Upgrade Apache Doris versions 4.1.0 through 4.1.3 to version 4.1.4.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Doris