← Retour aux CVEs
CVE-2024-27438
CRITICAL9.8
Description
Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. Once the attacker is authorized to create a JDBC catalog, he/she can use arbitrary driver jar file with unchecked code snippet. This code snippet will be run when catalog is initializing without any check. This issue affects Apache Doris: from 1.2.0 through 2.0.4. Users are recommended to upgrade to version 2.0.5 or 2.1.x, which fixes the issue.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie3/21/2024
Derniere modification6/17/2025
Sourcenvd
Observations honeypot0
Produits affectes
apache:doris
Faiblesses (CWE)
CWE-494
References
http://www.openwall.com/lists/oss-security/2024/03/21/1(security@apache.org)
https://lists.apache.org/thread/h95h82b0svlnwcg6c2xq4b08j6gwgczh(security@apache.org)
http://www.openwall.com/lists/oss-security/2024/03/21/1(af854a3a-2127-422b-91ae-364da2661108)
https://lists.apache.org/thread/h95h82b0svlnwcg6c2xq4b08j6gwgczh(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.