Skip to finding
important · RCE — Database

A privileged Apache Doris user can turn a crafted JDBC driver URL into code execution on the Frontend host.

Affects

Apache Doris, a distributed analytical database whose Java Frontend coordinates metadata, queries and cluster operations.

Apache establishes the Frontend execution boundary but does not publish the minimum required permission, precise URL form or fixed release.

Detail and 2 sources
Chain to watch
Recover the private fix or forthcoming release diff.→↓Map the vulnerable catalog operation through Doris privilege checks to the code-loading sink.→↓The minimum Doris permission, exact driver URL form and remediation release.
Unverified chainUse the fix diff to identify both the authorization gate and the resource-loading sink.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026