CVE-2023-41314 is a critical vulnerability affecting Apache Doris, allowing unauthenticated access to the /api/snapshot and /api/get_log_file endpoints. This flaw enables potential Denial of Service (DoS) attacks or arbitrary file retrieval from the frontend node. With a CVSS score of 8.2 (High), it presents a low-complexity attack vector with high impact on availability and low impact on confidentiality, requiring no user interaction or privileges. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability. Organizations using Apache Doris are strongly advised to upgrade to version 2.0.3 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.3CPE matchmatch criteria | cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.