Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris.
Application administrators can read arbitrary
files from the server filesystem through path traversal.
Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.
CVE ID: CVE-2024-48019
Vendor: Apache Software Foundation
Product: Apache Doris
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 13.01% (scored less or equal to compared to others)
EPSS Date: 2025-03-05 (when was this score calculated)