CVE-2025-58337P3MEDIUMCVSS 5.4≥ 0.1.0, < 0.6.02025-11-05
CVE-2025-58337 [MEDIUM] CWE-284 CVE-2025-58337: An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to impro
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions.
Impact:
Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications.
Recommended action for operators: Upgra
ghsanvdosv