← Vulnerability feed

Vulnerability record · CVE-2024-27438 · published 21 March 2024

CVE-2024-27438: Apache doris download of code without integrity check vulnerability

Apache · Doris

Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. Once the attacker is authorized to create a JDBC catalog, he/she can use arbitrary driver jar file with unchecked code snippet. This code snippet will be run when catalog is initializing without any check. This issue affects Apache Doris: from 1.2.0 through 2.0.4. Users are recommended to upgrade to version 2.0.5 or 2.1.x, which fixes the issue.

9.8 CVSS 3.1 Critical EPSS 0.96% · top 39.9% CWE-494 · Download of code without integrity check
9.8CVSS 3.1 base score
0.96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. Once the attacker is authorized to create a JDBC catalog, he/she can use arbitrary driver jar file with unchecked code snippet. This code snippet will be run when catalog is initializing without any check. This issue affects Apache Doris: from 1.2.0 through 2.0.4. Users are recommended to upgrade to version 2.0.5 or 2.1.x, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27438 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-41313Apache doris vulnerabilityThe authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 +…EPSS 1.0%9.1CVE-2026-58319Apache doris missing authentication for critical function vulnerabilityCertain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …EPSS 0.75%8.2CVE-2023-41314Apache doris incorrect authorization vulnerabilityThe api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Plea…EPSS 0.90%7.5CVE-2022-23942Apache doris hard-coded credentials vulnerabilityApache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.EPSS 3.5%5.4CVE-2024-48019Apache doris path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in …EPSS 1.0%5.3CVE-2024-26307Apache doris race condition vulnerabilityPossible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out…EPSS 0.22%7.8CVE-2026-3502TrueConf Client update download lacks integrity check, enabling code executionTrueConf Client downloads application update code and applies it without verifying its integrity (CWE-494). An attacker who can influence the update …KEVEPSS 0.33%analysed7.7CVE-2025-15556Notepad++ WinGUp updater lacks update integrity verificationNotepad++ versions prior to 8.8.9 use the WinGUp updater, which downloads update metadata and installers without cryptographic verification. An attac…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2024-27438), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.