CVE-2023-41313: Apache Doris

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.

Affected products

  • Apache Doris: before 1.2.8 (fixed in 1.2.8)

Published 2024-03-12. Last modified 2026-06-17.