Doris

Vendor:

First CVE: Apr 26, 2022 · Active for 4 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Doris over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 26, 2022
4 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Doris7 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could pe
Jul 14, 20269.141NONO
Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. On
Mar 21, 20249.829NONO
The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this iss
Mar 12, 20249.829NONO
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
Apr 26, 20227.526NONO
The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix thes
Dec 18, 20238.224NONO
Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding
Mar 21, 20245.319NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application adm
Feb 4, 20255.418NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Doris

Top CWEs

Versions

No cataloged versions.