Impact
An authentication misconfiguration in Apache Doris allows a user who is already authenticated to bypass the system’s privilege checks and read data that the user should not be able to access. This privilege escalation results in the accidental disclosure of sensitive information. The weakness is classified as a permissions and access control failure (CWE‑863).
Affected Systems
The vulnerability affects all versions of Apache Doris from 2.0.0 up to 2.1.*, from 3.0.0 up to 3.0.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3. The vendor is the Apache Software Foundation and the product is Apache Doris.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability can be leveraged by any authenticated user and therefore does not require an additional foothold in the network. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, but the ability to extract sensitive data without authorization makes it a serious business threat. In practice an attacker would need only a valid user session to trigger the bypass and view restricted data; however, the low EPSS score indicates that real-world exploitation is considered unlikely.
OpenCVE Enrichment