Lucene search

K
cvelistApacheCVELIST:CVE-2023-41313
HistoryMar 12, 2024 - 10:16 a.m.

CVE-2023-41313 Apache Doris: Timing Attack weakness

2024-03-1210:16:23
CWE-208
apache
www.cve.org
3
apache doris
authentication
timing attack
upgrade

AI Score

7

Confidence

Low

EPSS

0

Percentile

9.0%

The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks.
Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache Doris",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "1.2.8",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

AI Score

7

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2023-41313