CVE-2023-41313
CVE-2023-41313 is a critical-severity vulnerability in Apache Doris with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-208.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 1% (61st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2023-45829
- Weakness: CWE-208
- Affected product: Apache Doris
- Published:
- Last modified:
Description
The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.
Frequently asked questions
- What is CVE-2023-41313?
- The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.
- How severe is CVE-2023-41313?
- CVE-2023-41313 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-41313 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (61st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-41313?
- CVE-2023-41313 affects Apache Doris. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-41313?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2023-41313 have an EU (EUVD) identifier?
- Yes. CVE-2023-41313 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2023-45829.
- When was CVE-2023-41313 published?
- CVE-2023-41313 was published on 2024-03-12 and last updated on 2026-06-17.
References
- http://www.openwall.com/lists/oss-security/2024/03/10/2
- https://lists.apache.org/thread/jqczy3vxzs6q6rz9o0626j5nks9fnv95
Affected products (1)
- cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Doris
- CVE-2024-27438 — Critical (CVSS 9.8): Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is…
- CVE-2026-58319 — Critical (CVSS 9.1): Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated…
- CVE-2023-41314 — High (CVSS 8.2): The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get…
- CVE-2022-23942 — High (CVSS 7.5): Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may…
- CVE-2024-48019 — Medium (CVSS 5.4): Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to…
- CVE-2024-26307 — Medium (CVSS 5.3): Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of…
All CVEs affecting Apache Doris →
Other CWE-208 vulnerabilities
- CVE-2026-16315 — High (CVSS 8.7): OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend…
- CVE-2024-42512 — High (CVSS 8.6): Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass…
- CVE-2026-43606 — High (CVSS 8.5): Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local…
- CVE-2025-53940 — High (CVSS 8.5): Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central…
- CVE-2026-16731 — High (CVSS 8.3): OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend…
- CVE-2026-69247 — High (CVSS 8.2): cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0…