5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Description
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions.
Impact:
Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications.
Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).
Impact:
Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications.
Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).
Basic Information
ID
CVE-2025-58337
Source
apache
Published
Nov 5, 2025 at 09:26
Modified
Nov 6, 2025 at 15:55
Affected Product
Vendor
Apache Software Foundation
Product
Apache Doris-MCP-Server
Version
0.1.0
Affected Versions
Apache Software Foundation Apache Doris-MCP-Server 0.1.0