Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Doris Mcp Server
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-58337 1 Apache 1 Doris Mcp Server 2025-11-12 N/A 5.4 MEDIUM
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions. Impact: Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications. Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).