Impact
Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to execute arbitrary code on the FrontEnd. The vulnerability enables an attacker already possessing privileged access to inject malicious commands that are interpreted by the database engine, leading to full control over the server instance. Such a flaw directly compromises confidentiality, integrity, and availability by allowing unrestricted code execution.
Affected Systems
The affected product is Apache Doris, version(s) unspecified, provided by the Apache Software Foundation. No specific version window is listed in the CNA data.
Risk and Exploitability
The risk is high due to the remote code execution capability, yet the EPSS score indicates a very low exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog. Attackers would likely exploit the flaw through a specially crafted JDBC connection string originating from a privileged user, making the attack vector internal but still capable of elevating to a full remote compromise of the FE.
OpenCVE Enrichment