NA

CVE-2023-41313

Published: 12/03/2024 Updated: 01/05/2024

Vulnerability Summary

The authentication method in Apache Doris versions prior to 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.

Vulnerability Trend

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2023-41313: Apache Doris: Timing Attack weakness <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Mingyu Chen ...