CVE-2024-48019: Apache Doris
Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application administrators can read arbitrary files from the server filesystem through path traversal. Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.
Affected products
- Apache Doris: from 2.1.0, before 2.1.8 (fixed in 2.1.8); from 3.0.0, before 3.0.3 (fixed in 3.0.3)
Published 2025-02-04. Last modified 2026-06-17.