CVE-2025-58337
published 2025-11-05CVE-2025-58337: An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have…
PriorityP335medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.34%
25.8th percentile
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions.
Impact:
Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications.
Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | doris_mcp_server | < 0.6.0 | 0.6.0 |
| apache_software_foundation | apache_doris-mcp-server | >= 0 < 0.6.0 | 0.6.0 |
| apache_software_foundation | apache_doris-mcp-server | >= 0.1.0 < 0.6.0 | 0.6.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
ghsa·2025-11-05
CVE-2025-58337 [MEDIUM] CWE-284 Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions.
Impact:
Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications.
Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).
OSV
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
osv·2025-11-05
CVE-2025-58337 [MEDIUM] Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions.
Impact:
Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications.
Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-05
Published