← Vulnerability feed

Vulnerability record · CVE-2023-41314 · published 18 December 2023

CVE-2023-41314: Apache doris incorrect authorization vulnerability

Apache · Doris

The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.

8.2 CVSS 3.1 High EPSS 0.90% · top 42.0% CWE-863 · Incorrect authorization
8.2CVSS 3.1 base score
0.90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-41314 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27438Apache doris download of code without integrity check vulnerabilityDownload of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting …EPSS 0.96%9.8CVE-2023-41313Apache doris vulnerabilityThe authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 +…EPSS 1.0%9.1CVE-2026-58319Apache doris missing authentication for critical function vulnerabilityCertain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …EPSS 0.75%7.5CVE-2022-23942Apache doris hard-coded credentials vulnerabilityApache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.EPSS 3.5%5.4CVE-2024-48019Apache doris path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in …EPSS 1.0%5.3CVE-2024-26307Apache doris race condition vulnerabilityPossible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out…EPSS 0.22%9.1CVE-2026-71362Adobe commerce incorrect authorization vulnerabilityAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…KEVEPSS 88%8.8CVE-2026-42016JFrog Artifactory token scope bypass enables privilege escalationJFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond…KEVEPSS 8.6%analysed

Source: NIST National Vulnerability Database (record CVE-2023-41314), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.