CVE-2025-58337 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have…
Medium CVSS: 5.4

CVE-2025-58337

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions.


Impact:

Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications.




Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).
Vendor
Apache
Product
Doris Mcp Server
CWE
CWE-284
Yayın Tarihi
2025-11-05 10:15:36
Güncelleme
2025-11-12 20:51:18
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar