CVE-2023-41314
CVE-2023-41314 is a high-severity vulnerability in Apache Doris with a CVSS 3.x base score of 8.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-863.
Key facts
- Severity: High (CVSS 3.x base score 8.2)
- EPSS exploit prediction: 1% (57th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-863
- Affected product: Apache Doris
- Published:
- Last modified:
Description
The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.
Frequently asked questions
- What is CVE-2023-41314?
- The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.
- How severe is CVE-2023-41314?
- CVE-2023-41314 has a CVSS 3.x base score of 8.2, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability high.
- Is CVE-2023-41314 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (57th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-41314?
- CVE-2023-41314 affects Apache Doris. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-41314?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2023-41314 published?
- CVE-2023-41314 was published on 2023-12-18 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Doris
- CVE-2024-27438 — Critical (CVSS 9.8): Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is…
- CVE-2023-41313 — Critical (CVSS 9.8): The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended…
- CVE-2026-58319 — Critical (CVSS 9.1): Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated…
- CVE-2022-23942 — High (CVSS 7.5): Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may…
- CVE-2024-48019 — Medium (CVSS 5.4): Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to…
- CVE-2024-26307 — Medium (CVSS 5.3): Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of…
All CVEs affecting Apache Doris →
Other CWE-863 (Incorrect Authorization) vulnerabilities
- CVE-2026-69555 — Critical (CVSS 10.0): Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-71398 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-27302 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-48449 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-48286 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization…
- CVE-2026-48303 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization…
Browse all CWE-863 (Incorrect Authorization) vulnerabilities →