Apache Doris MCP Server
cpe:2.3:a:apache:doris:*:*:*:*:*:*:*
- >= 0.1.0, < 0.6.1
A SQL injection vulnerability has been identified in Apache Doris MCP Server versions prior to 0.6.1. This vulnerability arises from improper handling of query context, which may allow the execution of unintended SQL statements. Additionally, it can bypass intended query validation and access restrictions through the MCP query execution interface.
Exploitation of this vulnerability could lead to unauthorized execution of SQL statements, potentially allowing attackers to manipulate the database in unintended ways.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.