CVE-2024-48019

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
04/02/2025
Last modified:
09/06/2025

Description

Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;), Files or Directories Accessible to External Parties vulnerability in Apache Doris.<br /> <br /> <br /> Application administrators can read arbitrary<br /> files from the server filesystem through path traversal.<br /> <br /> <br /> Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.8 (excluding)
cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.3 (excluding)