Executive brief
Apache Doris is a distributed data warehouse used for analytics. A privileged user can bypass URL validation when configuring JDBC database drivers, allowing them to execute arbitrary code on the system's front-end node. This requires the attacker to have elevated privileges within Doris.
Technical details
The vulnerability involves insufficient validation of JDBC driver URLs in Apache Doris, allowing a privileged user to inject malicious configurations that execute remote code on the front-end (FE) node. The attack requires high-level privileges within Doris and leverages the JDBC connection mechanism. A fix is available in newer versions.
Affected products
- Apache Doris 2.0.5 through 4.1.3
Timeline
- 2026-09-23: disclosed