Lucene search

K
vulnrichmentApacheVULNRICHMENT:CVE-2023-41313
HistoryMar 12, 2024 - 10:16 a.m.

CVE-2023-41313 Apache Doris: Timing Attack weakness

2024-03-1210:16:23
CWE-208
apache
github.com
1
apache doris
authentication
timing attack
cve-2023-41313
upgrade
version 2.0.0
version 1.2.8
vulnerability fix

AI Score

7.1

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks.
Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*"
    ],
    "vendor": "apache",
    "product": "doris",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "1.2.8",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

7.1

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-41313