Apache Doris: Missing API authentication allowed DoS
CVE-2023-41314
8.2HIGH
What is CVE-2023-41314?
The Apache API has a vulnerability that allows unauthenticated access to critical endpoints, specifically /api/snapshot and /api/get_log_file. This access could lead to denial-of-service (DoS) attacks, as well as the potential for attackers to retrieve arbitrary files from the frontend node, compromising sensitive information. Users are strongly advised to upgrade to version 2.0.3 or later to mitigate these risks.
Affected Version(s)
Apache Doris 1.2.0 <= 2.0.3