Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-26307


Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4. Users are recommended to upgrade to version 2.0.4, which fixes the issue.


Published

2024-03-21T10:15:07.527

Last Modified

2025-06-17T13:50:12.777

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache doris < 1.2.8 Yes
Application apache doris < 2.0.4 Yes

References