CVE-2024-26307

Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4. Users are recommended to upgrade to version 2.0.4, which fixes the issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*

History

17 Jun 2025, 13:50

Type Values Removed Values Added
CPE cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*
First Time Apache
Apache doris
References () https://lists.apache.org/thread/5shhw8x8m271hd2wfwzqzwgf36pmc4pl - () https://lists.apache.org/thread/5shhw8x8m271hd2wfwzqzwgf36pmc4pl - Mailing List
References () http://www.openwall.com/lists/oss-security/2024/03/21/2 - () http://www.openwall.com/lists/oss-security/2024/03/21/2 - Mailing List

13 Feb 2025, 18:17

Type Values Removed Values Added
CWE CWE-362
Summary Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4. Users are recommended to upgrade to version 2.0.4, which fixes the issue. Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4. Users are recommended to upgrade to version 2.0.4, which fixes the issue.

01 May 2024, 17:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/03/21/2 -

21 Mar 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-21 10:15

Updated : 2025-06-17 13:50


NVD link : CVE-2024-26307

Mitre link : CVE-2024-26307


JSON object : View

Products Affected

apache

  • doris
CWE

No CWE.